CVE-2026-54794: SSRF
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell OpenManage Enterpriseto a version that resolves this vulnerability.Fixed in 4.7.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of Dell OpenManage Enterprise running a version earlier than 4.7.0 are affected if they are reachable remotely by an unauthenticated attacker.
What access does an attacker need to exploit the vulnerability?
The vulnerability can potentially be exploited remotely without authentication or user interaction. The provided information does not identify any additional configuration prerequisite.
What is the expected impact of successful exploitation?
Successful exploitation could lead to information exposure. The supplied impact vector indicates low confidentiality and integrity impact, with no availability impact.
What should be done to remediate the issue?
Update Dell OpenManage Enterprise to version 4.7.0 or later. The provided data does not specify an alternative mitigation if upgrading cannot be performed immediately.