GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: unauthenticated path traversal exposes arbitrary files from the managed node

CVSS 7.5CVE-2026-81481Firmware, BMC & network fabriccurated

Impact

An unauthenticated network attacker can read files outside the intended directory through the OMSA service. On a GPU host that filesystem holds kubelet and container runtime configuration, service-account tokens, driver and fabric configuration, and often credentials for the scheduler or storage - so file read on one node is a credential-harvesting step into the wider cluster. Dell does not state which paths are reachable. CVE-2026-81453 is a separate traversal that requires a low-privileged account.

Who can reach it

Network access to the OMSA service on a managed node. No authentication required.

What to do

Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services. Keep the OMSA port off any tenant-reachable network until patched, and treat credentials stored on exposed nodes as candidates for rotation.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.