{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81447","assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","state":"PUBLISHED","assignerShortName":"dell","dateReserved":"2026-08-26T20:04:54.730Z","datePublished":"2026-09-17T14:47:54.450Z","dateUpdated":"2026-09-18T03:56:02.106Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell","dateUpdated":"2026-09-17T14:47:54.450Z"},"datePublic":"2026-09-08T06:30:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-295","description":"CWE-295: Improper Certificate Validation","type":"CWE"}]}],"affected":[{"vendor":"Dell","product":"OpenManage Server Administrator Managed Node (Patch) for Windows","versions":[{"status":"affected","version":"0","lessThan":"11.1.0.3","versionType":"semver"}],"defaultStatus":"unaffected"},{"vendor":"Dell","product":"OpenManage Server Administrator Managed Node for RHEL 8.10","versions":[{"status":"affected","version":"0","lessThan":"11.1.0.3","versionType":"semver"}],"defaultStatus":"unaffected"},{"vendor":"Dell","product":"OpenManage Server Administrator Managed Node for RHEL 9.4","versions":[{"status":"affected","version":"0","lessThan":"11.1.0.3","versionType":"semver"}],"defaultStatus":"unaffected"},{"vendor":"Dell","product":"OpenManage Server Administrator Managed Node for SLES 15","versions":[{"status":"affected","version":"0","lessThan":"11.1.0.3","versionType":"semver"}],"defaultStatus":"unaffected"},{"vendor":"Dell","product":"OpenManage Server Administrator Managed Node for Ubuntu 22.04","versions":[{"status":"affected","version":"0","lessThan":"11.1.0.3","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.","supportingMedia":[{"type":"text/html","base64":false,"value":"Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering."}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":6.8,"vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}}],"credits":[{"lang":"en","value":"Dell would like to thank saltedfish for reporting these issues.","type":"other"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-81447"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-18T03:56:02.106Z"}}]}}