CVE-2026-101207: OS Command Injection
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell OpenManage Integration with Microsoft Windows Admin Centerto a version that resolves this vulnerability.Fixed in 3.7.0
Event History
Frequently Asked Questions
Which deployments are affected?
Dell OpenManage Integration with Microsoft Windows Admin Center versions earlier than 3.7.0 are affected.
What level of access does an attacker need?
An attacker needs remote access and low-privileged access to exploit the issue. No user interaction is required.
What could successful exploitation allow?
Successful exploitation could lead to remote code execution with high impact to confidentiality, integrity, and availability.