{"api_version":"1","generated_at":"2026-09-18T01:54:27+00:00","cve":"CVE-2026-81447","urls":{"html":"https://cve.report/CVE-2026-81447","api":"https://cve.report/api/cve/CVE-2026-81447.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-81447","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-81447"},"summary":{"title":"CVE-2026-81447","description":"Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.","state":"PUBLISHED","assigner":"dell","published_at":"2026-09-17 15:16:52","updated_at":"2026-09-17 20:18:40"},"problem_types":["CWE-295","CWE-295 CWE-295: Improper Certificate Validation"],"metrics":[{"version":"3.1","source":"security_alert@emc.com","type":"Secondary","score":"6.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv","name":"https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv","refsource":"security_alert@emc.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81447","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81447","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Dell","product":"OpenManage Server Administrator Managed Node (Patch) for Windows","version":"affected 11.1.0.3 semver","platforms":[]},{"source":"CNA","vendor":"Dell","product":"OpenManage Server Administrator Managed Node for RHEL 8.10","version":"affected 11.1.0.3 semver","platforms":[]},{"source":"CNA","vendor":"Dell","product":"OpenManage Server Administrator Managed Node for RHEL 9.4","version":"affected 11.1.0.3 semver","platforms":[]},{"source":"CNA","vendor":"Dell","product":"OpenManage Server Administrator Managed Node for SLES 15","version":"affected 11.1.0.3 semver","platforms":[]},{"source":"CNA","vendor":"Dell","product":"OpenManage Server Administrator Managed Node for Ubuntu 22.04","version":"affected 11.1.0.3 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Dell would like to thank saltedfish for reporting these issues.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-81447","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-17T17:15:08.614487Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-17T19:19:37.987Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"OpenManage Server Administrator Managed Node (Patch) for Windows","vendor":"Dell","versions":[{"lessThan":"11.1.0.3","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"OpenManage Server Administrator Managed Node for RHEL 8.10","vendor":"Dell","versions":[{"lessThan":"11.1.0.3","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"OpenManage Server Administrator Managed Node for RHEL 9.4","vendor":"Dell","versions":[{"lessThan":"11.1.0.3","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"OpenManage Server Administrator Managed Node for SLES 15","vendor":"Dell","versions":[{"lessThan":"11.1.0.3","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"OpenManage Server Administrator Managed Node for Ubuntu 22.04","vendor":"Dell","versions":[{"lessThan":"11.1.0.3","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"other","value":"Dell would like to thank saltedfish for reporting these issues."}],"datePublic":"2026-09-08T06:30:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering."}],"value":"Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"CWE-295: Improper Certificate Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-17T14:47:54.450Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"tags":["vendor-advisory"],"url":"https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2026-81447","datePublished":"2026-09-17T14:47:54.450Z","dateReserved":"2026-08-26T20:04:54.730Z","dateUpdated":"2026-09-17T19:19:37.987Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 15:16:52","lastModifiedDate":"2026-09-17 20:18:40","problem_types":["CWE-295","CWE-295 CWE-295: Improper Certificate Validation"],"metrics":{"cvssMetricV31":[{"source":"security_alert@emc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-17T17:15:08.614487Z","id":"CVE-2026-81447","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"81447","Ordinal":"1","Title":"CVE-2026-81447","CVE":"CVE-2026-81447","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"81447","Ordinal":"1","NoteData":"Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.","Type":"Description","Title":"CVE-2026-81447"}]}}}