CVE-2026-54796: OS Command Injection
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell OpenManage Enterpriseto a version that resolves this vulnerability.Fixed in 4.7.0
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires a high-privileged attacker with remote access to Dell OpenManage Enterprise. The issue is remotely reachable and does not require user interaction.
Which versions are affected?
Dell OpenManage Enterprise versions earlier than 4.7.0 are affected. Version 4.7.0 is not identified as affected by the provided information.
What is the potential impact of successful exploitation?
A successful attacker could execute operating system commands. The stated impact includes high confidentiality, integrity, and availability impact.