CVE-2026-56088
published 2026-08-19CVE-2026-56088: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.30%
23.0th percentile
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | openmanage_enterprise | < 4.7.0 or later | 4.7.0 or later |
| dell | openmanage_enterprise | < 4.7.0 | 4.7.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Dell OpenManage Enterprise up to 4.6.x sql injection
vuldb·2026-08-24·CVSS 8.8
CVE-2026-56088 [HIGH] Dell OpenManage Enterprise up to 4.6.x sql injection
A vulnerability identified as critical has been detected in Dell OpenManage Enterprise up to 4.6.x. This issue affects some unknown processing. Performing a manipulation results in sql injection.
This vulnerability is known as CVE-2026-56088. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
GHSA
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
ghsa_unreviewed·2026-08-19
CVE-2026-56088 [HIGH] CWE-89 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published