CVE-2026-70422
published 2026-08-19CVE-2026-70422: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.30%
23.0th percentile
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | openmanage_enterprise | < 4.7.0 or later | 4.7.0 or later |
| dell | openmanage_enterprise | < 4.7.0 | 4.7.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Dell OpenManage Enterprise up to 4.6.x sql injection
vuldb·2026-08-24·CVSS 8.8
CVE-2026-70422 [HIGH] Dell OpenManage Enterprise up to 4.6.x sql injection
A vulnerability classified as critical was found in Dell OpenManage Enterprise up to 4.6.x. Affected by this issue is some unknown functionality. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2026-70422. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
ghsa_unreviewed·2026-08-19
CVE-2026-70422 [HIGH] CWE-89 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published