DSA-2026-359: Security Update for Dell OpenManage Enterprise Vulnerabilities
Summary: Dell OpenManage Enterprise remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
|
Third-party Component |
CVEs |
More Information |
|
Go standard library |
CVE-2025-61729 |
|
|
glibc, encoding/pem, net/url, encoding/asn1, crypto/tls, database/sql, net/textproto, crypto/x509 |
CVE-2025-61723, CVE-2025-47912, CVE-2025-61726, CVE-2025-58185, CVE-2025-58189, CVE-2025-61730, CVE-2025-68121, CVE-2025-47907, CVE-2025-61727, CVE-2025-61729, CVE-2025-58187, CVE-2025-58188, CVE-2025-61725 |
|
|
yaml for Go |
CVE-2022-28948 |
|
|
pgx |
CVE-2024-27304 |
|
|
golang.org/x/net |
CVE-2023-45288 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-54793 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
4.6 |
|
|
CVE-2026-54794 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
7.2 |
|
|
CVE-2026-54795 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
8.8 |
|
|
CVE-2026-54796 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
7.2 |
|
|
CVE-2026-56088 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
7.1 |
|
|
CVE-2026-70421 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.2 |
|
|
CVE-2026-70422 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
8.1 |
|
|
CVE-2026-70423 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
6.5 |
|
|
CVE-2026-70424 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
6.5 |
|
|
CVE-2026-71176 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
8.8 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-54793 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
4.6 |
|
|
CVE-2026-54794 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
7.2 |
|
|
CVE-2026-54795 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
8.8 |
|
|
CVE-2026-54796 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
7.2 |
|
|
CVE-2026-56088 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
7.1 |
|
|
CVE-2026-70421 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.2 |
|
|
CVE-2026-70422 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
8.1 |
|
|
CVE-2026-70423 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
6.5 |
|
|
CVE-2026-70424 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
6.5 |
|
|
CVE-2026-71176 |
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
8.8 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell OpenManage Enterprise |
Versions prior to 4.7.0 |
Version 4.7.0 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=c6vy6 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell OpenManage Enterprise |
Versions prior to 4.7.0 |
Version 4.7.0 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=c6vy6 |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2026-08-17 |
Initial release |
Acknowledgements
CVE-2026-54793, CVE-2026-56088, CVE-2026-70421, CVE-2026-70422, CVE-2026-70423, CVE-2026-70424, CVE-2026-71176: Dell would like to thank WinD39 - Huynh Dinh Vu for reporting these issues.