Sceawere

Vulnerability Detail

CVE-2026-56794UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell OMSA Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Dell
Product
Dell OpenManage Server Administrator Managed Node (Patch) for Windows
Attack Type
CWE-23: Relative Path Traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-07T13:16:52.633Z",
  "pubdate": "2026-08-07T13:16:52.633Z",
  "executiveSummary": "Dell OpenManage Server Administrator (OMSA), in versions prior to 11.1.0.2, suffers from a Relative Path Traversal vulnerability.\nThis security flaw enables a low-privileged threat actor with remote access capabilities to bypass directory restrictions and gain unauthorized filesystem access on the targeted host.\nThe vulnerability exposes sensitive system components and data to potential compromise, significantly increasing the risk surface of enterprise environments utilizing the affected management software.\nSuccessful exploitation requires remote network access to the management service and authenticated low-privileged user capabilities, allowing the attacker to traverse outside the intended web root or operational directory.\nOrganizations running vulnerable instances face severe integrity and confidentiality risks, as unauthorized filesystem traversal can facilitate further system-level attacks.",
  "technicalDetails": "The vulnerability resides in the request handling implementation of Dell OpenManage Server Administrator prior to version 11.1.0.2, specifically within the component responsible for processing file or resource retrieval requests.\nThe root cause is improper sanitization and validation of user-supplied input containing relative path sequences, such as dot-dot-slash (../) patterns, enabling the manipulation of directory paths during file resolution.\nAn attacker possessing low-privileged remote access can construct a specially crafted HTTP request or payload incorporating traversal sequences to target arbitrary files within the underlying operating system's filesystem.\nThe attack flow begins when the vulnerable application receives the malicious request containing the path traversal sequences. Failing to adequately validate or restrict the input against a securely defined root directory, the application interprets the relative path and navigates upward in the directory hierarchy.\nThe component subsequently accesses, reads, or potentially interacts with files outside the intended operational scope, returning the requested resource or executing operations based on the execution context of the service.\nBecause Dell OpenManage Server Administrator often runs with elevated system privileges to manage hardware and administrative functions, the resulting filesystem access can expose highly sensitive configuration files, system data, or operational logs.\nPrerequisites for exploitation include network exposure of the Dell OpenManage Server Administrator service and valid credentials yielding low-privileged access to the application interface."
}
CVE-2026-56794: Dell OMSA Path Traversal Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere