GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: remote heap overflow gives code execution to a high-privileged account

CVSS 7.2CVE-2026-81477Firmware, BMC & network fabriccurated

Impact

A remote attacker holding a high-privileged OMSA account can overflow a heap buffer and execute code in the agent's context on the managed node. Because it needs administrative OMSA credentials it is mainly a path from management-plane credential theft to host code execution on the GPU node - a stolen or reused OMSA admin password becomes root-equivalent on every node it works on. Distinct from CVE-2026-81474 (local, low-privileged) and CVE-2026-81480 (stack overflow).

Who can reach it

Network access to OMSA with a high-privileged (administrative) OMSA account.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Rotating shared OMSA administrative credentials is worth doing alongside the patch.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.