DIRAS TAKE
Urgent: this is an unauthenticated remote-access vulnerability and Dell issued a fixed release (11.1.0.2); prioritize installing the update or isolating the service from untrusted networks immediately.
What is CVE-2026-56793?
Unauthenticated remote attackers can gain unauthorized access to Dell OpenManage Server Administrator Managed Node; tracked as CVE-2026-56793. The flaw affects OpenManage Server Administrator Managed Node releases before 11.1.0.2 across Windows, RHEL 8.10, RHEL 9.4 and SLES 15 branches. An attacker only needs remote network access to the management service—no valid credentials or user interaction is required—to attempt exploitation that could lead to full confidentiality, integrity, and availability impact. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Dell OpenManage Server Administrator Managed Node (Patch) for Windows are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| OpenManage Server Administrator Managed Node (Patch) for Windows 11.x | before 11.1.0.2 | 11.1.0.2 |
| Dell OpenManage Server Administrator Managed Node for RHEL 8.10 11.x | before 11.1.0.2 | 11.1.0.2 |
| Dell OpenManage Server Administrator Managed Node for RHEL 9.4 11.x | before 11.1.0.2 | 11.1.0.2 |
| Dell OpenManage Server Administrator Managed Node for SLES 15 11.x | before 11.1.0.2 | 11.1.0.2 |
Is CVE-2026-56793 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-56793
- Upgrade OpenManage Server Administrator Managed Node to version 11.1.0.2 on all affected platforms.
- If you cannot patch immediately, restrict network exposure of the management service to trusted management networks and VPNs.
- Block or filter access to management ports at network perimeter devices and zero-trust gateways.
- Monitor OpenManage logs and host telemetry for anomalous authentication attempts and unauthorized actions, and follow Dell's guidance.
Frequently asked questions
Is CVE-2026-56793 being actively exploited?
There are no public reports of active exploitation of CVE-2026-56793 as of 2026-09-29.
Which OpenManage Server Administrator versions are affected by CVE-2026-56793?
OpenManage Server Administrator Managed Node releases before 11.1.0.2 for Windows, RHEL 8.10, RHEL 9.4 and SLES 15 are listed as affected.
Is there a patch for CVE-2026-56793?
Yes. Dell published a fixed release: OpenManage Server Administrator Managed Node version 11.1.0.2.
Does CVE-2026-56793 require authentication?
No. The vulnerability allows unauthenticated remote access to Dell OpenManage Server Administrator, so no valid credentials are required for an attacker to attempt exploitation.
References
- nvd.nist.gov/vuln/detail/CVE-2026-56793
- cve.org/CVERecord?id=CVE-2026-56793
- dell.com/support/kbdoc/en-us/000494958/dsa-2026-326-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilities
- All Dell CVEs on CVE Radar
- CVEs published in September 2026