TL;DR
Dell published an advisory covering four Dell Terraform Provider vulnerabilities. The most critical flaw disables TLS certificate validation in Redfish providers, exposing management traffic. Administrators must update the provider plugins to secure internal infrastructure provisioning.
CISA KEV isn't the only exploit signal. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy It Matters
Thousands of enterprise data centers deploy Terraform to automate Dell Server management. Consequently, security defects in these provisioning plugins expose highly privileged administrative credentials. The most severe defect carries a critical CVSS base score of 9.0. Dell clarified that this defect allows attackers to perform man-in-the-middle attacks to intercept Redfish BMC traffic. Currently, Dell confirmed no active exploitation in the wild. Additionally, researchers have not published any public proof-of-concept exploit code. However, unpatched servers remain highly susceptible to credential theft and unauthorized access. Therefore, mitigating these Dell Terraform Provider vulnerabilities is a top priority for IT operations.
How The Attack Works
These flaws target the HTTP transport and API error handling mechanisms. For CVE-2026-91881, the Redfish provider disables TLS verification unconditionally in the base transport layer. An unauthenticated remote attacker intercepts the plaintext data stream between the provider and the server endpoint. As Dell explicitly stated in the advisory, “TLS certificate verification is unconditionally disabled in the base HTTP transport.”
Other defects expose sensitive data directly. For instance, CVE-2026-91882 involves inserting sensitive information into externally accessible files during API error handling. Furthermore, CVE-2026-76113 exposes sensitive data to unauthorized actors inside the redfish_certificate resource. Finally, CVE-2026-91883 writes secure configuration data directly into plaintext log files.
Affected Versions
These defects impact multiple Terraform plugins for Dell servers. The Redfish provider is vulnerable in versions prior to 1.6.2. The OpenManage Enterprise (OME) provider is vulnerable in versions 1.0.0 through 1.2.3.
Patch Or Mitigation Steps
Administrators must upgrade their infrastructure provisioning plugins immediately. Dell released Redfish provider version 1.6.2 and OME provider version 1.2.4 to resolve these issues. You can verify the full remediation details via the official Dell security advisory on their support portal. Updating the modules restores certificate validation and prevents plaintext credential exposure.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!