Dell Openmanage Enterprise
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Dell Openmanage Enterprise.
By the Year
In 2026 there have been 10 vulnerabilities in Dell Openmanage Enterprise with an average score of 7.2 out of ten. Last year, in 2025 Openmanage Enterprise had 1 security vulnerability published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.70.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 10 | 7.20 |
| 2025 | 1 | 6.50 |
| 2024 | 6 | 6.98 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 8.80 |
| 2021 | 4 | 8.08 |
It may take a day or so for new Openmanage Enterprise vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Openmanage Enterprise Security Vulnerabilities
Dell OpenManage Enterprise <4.7.0 SQLi Vulnerability (Improper Escape)
CVE-2026-71176
8.8 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
SQL Injection
XSS in Dell OpenManage Enterprise <4.7.0 (Improper Input Neutralization)
CVE-2026-54793
4.6 - Medium
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
XSS
Dell OpenManage Enterprise SSRF before 4.7.0 Unauthenticated Graph API
CVE-2026-54794
7.2 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
SSRF
Dell OpenManage Enterprise 4.6.x Path Traversal Before 4.7.0
CVE-2026-70424
6.5 - Medium
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Directory traversal
Dell OpenManage Enterprise <4.7.0: SQL Injection via Script Injection
CVE-2026-70422
8.1 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
SQL Injection
Dell OpenManage Enterprise 4.7.0- Prev, XEE Improper Restriction Exposing Info
CVE-2026-70423
6.5 - Medium
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
XXE
Dell OM Enterprise SQLi before v4.7.0 (Improper Neutralization of Special Elements)
CVE-2026-56088
7.1 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
SQL Injection
Dell OM Enterprise <4.7.0 OS Cmd Inj CVE-2026-54795
CVE-2026-54795
8.8 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Shell injection
Dell OpenManage Enterprise Improper Privilege Management (4.6)
CVE-2026-70421
7.2 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Improper Privilege Management
Dell OpenManage Enterprise <4.7.0 OS Command Injection (High Privileged Remote)
CVE-2026-54796
7.2 - High
- August 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Shell injection
Dell OpenManage Enterprise 3.10-4.2 Insecure Log of Sensitive Data (Backup/Restore)
CVE-2025-38745
6.5 - Medium
- August 14, 2025
Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backup and Restore. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Insertion of Sensitive Information into Log File
Dell OME 4.1 and prior vulnerable to low-priv code injection (CVE-2024-45766)
CVE-2024-45766
8.8 - High
- October 17, 2024
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Code Injection
SQL Injection in Dell OME 4.1- (OME 4.1 & prior) leading to info disclosure
CVE-2024-45767
6.5 - Medium
- October 17, 2024
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
SQL Injection
Improper Access Control in Dell OpenManage Enterprise 3.10 & 4.0
CVE-2024-28978
6.5 - Medium
- May 01, 2024
Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to unauthorized access to resources.
Authorization
XSS in Dell OpenManage Enterprise <=4.1.0 (Improper Neutralization)
CVE-2024-28979
4.8 - Medium
- May 01, 2024
Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
XSS
Dell OpenManage Enterprise 4.0.x Info Leak Enables Privilege Escalation
CVE-2024-28961
7.8 - High
- April 29, 2024
Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.
Insufficiently Protected Credentials
OpenManage Enterprise v4.0- Prior Path Traversal (CVE-2024-25944)
CVE-2024-25944
7.5 - High
- March 29, 2024
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application.
Directory traversal
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability
CVE-2022-26857
8.8 - High
- May 26, 2022
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.
Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00
CVE-2021-21596
8.8 - High
- August 09, 2021
Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the immediate subnet may potentially exploit this vulnerability leading to information disclosure and a possible elevation of privileges.
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability
CVE-2021-21564
9.8 - Critical
- August 09, 2021
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to hijack an elevated session or perform unauthorized actions by sending malformed data.
authentification
Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability
CVE-2021-21584
6.5 - Medium
- August 09, 2021
Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC server credentials.
Information Disclosure
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools
CVE-2021-21585
7.2 - High
- August 09, 2021
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this vulnerability to execute arbitrary OS commands.
Shell injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Dell Openmanage Enterprise or by Dell? Click the Watch button to subscribe.