Sceawere

Vulnerability Detail

CVE-2026-71176UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell OpenManage Enterprise SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Dell
Product
OpenManage Enterprise
Attack Type
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-19T15:18:01.637Z",
  "pubdate": "2026-08-19T15:18:01.637Z",
  "executiveSummary": "Dell OpenManage Enterprise, in versions prior to 4.7.0, is affected by an Improper Neutralization of Special Elements used in an SQL Command, commonly known as SQL Injection. This security flaw introduces significant risk to organizational infrastructure by potentially exposing sensitive internal data managed by the application. The vulnerability can be exploited by an authenticated attacker possessing low privileges and remote network access to the system. Successful exploitation requires the capability to interact with vulnerable database query parameters through the application interface without necessitating complex prerequisite setups beyond standard low-privileged access. The implications of this vulnerability include unauthorized data retrieval, database interrogation, and potential compromise of confidentiality regarding stored enterprise data. Remediation requires applying the official vendor-supplied software update to eliminate the insecure query construction mechanism.",
  "technicalDetails": "The vulnerability resides within the database query handling architecture of Dell OpenManage Enterprise versions prior to 4.7.0. The root cause is categorized as CWE-89, stemming from insufficient sanitization, validation, and parameterization of user-supplied input data before incorporating it into dynamic SQL statements. Consequently, specialized characters and control syntax supplied by an attacker are interpreted directly by the database management system as executable command logic rather than literal string data.\nExploitation of this flaw occurs via remote network access vectors. An attacker authenticated with low privileges constructs malicious input payloads containing SQL syntax injection vectors. These payloads are delivered to vulnerable input parameters processed by the application's backend database components. Because the underlying application logic fails to properly neutralize special elements or enforce parameterized queries, the injected SQL commands are executed within the context of the database connection.\nThe attack flow proceeds as follows: First, the low-privileged attacker identifies application functionality that accepts user input and subsequently queries the backend database. Second, the attacker crafts a specialized input payload designed to manipulate the query logic, such as incorporating UNION-based operators or boolean conditions to extract unauthorized datasets. Third, the application forwards the unsanitized input directly to the database execution engine. Fourth, the database evaluates the modified query structure and returns unauthorized query results back through the application interface to the attacker.\nThe post-exploitation impact is primarily characterized by unauthorized information exposure. By leveraging the SQL injection vulnerability, an attacker can bypass standard access controls to read sensitive database contents, system metadata, or application data store records. The vulnerability requires network accessibility to the Dell OpenManage Enterprise interface and valid low-privileged authentication credentials, but does not inherently require high-level administrative privileges to execute the malicious queries."
}
CVE-2026-71176: Dell OpenManage Enterprise SQL Injection (HIGH Severity, CVSS: 8.8) - Sceawere