CVE-2026-54795: OS Command Injection
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell OpenManage Enterpriseto a version that resolves this vulnerability.Fixed in 4.7.0
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A low-privileged attacker with remote access to Dell OpenManage Enterprise could potentially exploit it. No user interaction is required.
Which deployments are affected?
Dell OpenManage Enterprise versions earlier than 4.7.0 are affected. The provided information does not state whether any particular default configuration is required.
What is the potential impact of successful exploitation?
Successful exploitation could lead to OS command execution. The listed impact includes high confidentiality, integrity, and availability effects.