CVE-2026-23855: OS Command Injection
Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell iDRAC9to a version that resolves this vulnerability.Fixed in 7.00.00.184 - Upgrade
Upgrade
Dell iDRAC9to a version that resolves this vulnerability.Fixed in 7.30.10.50 - Upgrade
Upgrade
Dell iDRAC10to a version that resolves this vulnerability.Fixed in 1.30.30.50
Event History
Frequently Asked Questions
Which systems are affected?
Affected systems are Dell iDRAC9 on 14G before 7.00.00.184, iDRAC9 on 15G/16G before 7.30.10.50, and Dell iDRAC10 on 17G before 1.30.30.50.
What access does an attacker need to exploit this issue?
An attacker needs remote access and high-privileged access to the affected iDRAC interface. No user interaction is required.
What could exploitation allow?
Successful exploitation could lead to OS command injection. The reported impact includes high potential impact to confidentiality, integrity, and availability.