GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: unauthenticated OS command injection gives remote execution on the managed node

CVSS 8.1CVE-2026-81476Firmware, BMC & network fabriccurated

Impact

OMSA passes externally supplied input into an OS command without neutralising special elements, so an unauthenticated network attacker can run commands in the context of the OMSA agent. That agent is privileged and sits on the host that runs the accelerators, so a compromise is host compromise on a GPU node plus control of that node's hardware management surface. Dell does not state which handler is affected.

Who can reach it

Network access to the OMSA service on a managed node. No authentication required.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Where the upgrade cannot be scheduled immediately, keep the OMSA port firewalled to the management VLAN or uninstall the agent. No vendor workaround is published.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.