GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: missing authentication on a critical function lets an unauthenticated attacker execute code

CVSS 8.1CVE-2026-81475Firmware, BMC & network fabriccurated

Impact

OMSA runs as a privileged agent on every Dell server it is installed on, and its web/agent service listens on the network. Dell states that an unauthenticated remote attacker can reach a critical function that is missing an authentication check and obtain remote execution. On a GPU fleet that means anyone who can reach the OMSA port on a management or host interface takes control of the node's hardware management agent, which runs with high privilege on the host that also owns the GPUs. Dell's advisory does not publish exploit detail or an attack-complexity narrative beyond the CVSS vector (AC:H).

Who can reach it

Network access to the OMSA service on a managed node. No authentication required.

What to do

Upgrade Dell OpenManage Server Administrator to 11.1.0.3 or later on every managed node (Windows, RHEL 8.10/9.4, SLES 15, Ubuntu 22.04 packages are all affected) and restart the OMSA services. Until then, restrict OMSA's listening port to the management network only, or remove OMSA from nodes that do not need it. Dell's DSA-2026-403 does not describe a configuration-only mitigation.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.