CVE-2026-23855
largeOS Command Injection in Dell iDRAC9 and iDRAC10 (High-Privilege)
Dell iDRAC9 and iDRAC10, the out-of-band remote management controllers embedded in 14th through 17th generation PowerEdge servers, contain an OS command injection flaw (CWE-78) in which special elements in input are not properly neutralized before being passed to the underlying operating system. The flaw is exploited remotely over the network (CVSS vector AV:N) by an attacker who has already obtained high-privileged credentials on the iDRAC interface; no user interaction is required. Successful exploitation allows arbitrary OS command execution on the management controller, with high impact to confidentiality, integrity, and availability. Anyone running unpatched iDRAC9 on 14G systems (prior to 7.00.00.184), iDRAC9 on 15G/16G systems (prior to 7.30.10.50), or iDRAC10 on 17G systems (prior to 1.30.30.50) is affected. There is currently no CISA KEV listing, no known public proof-of-concept, and no confirmed in-the-wild exploitation.
What to do: Upgrade iDRAC9 on 14th-generation PowerEdge to 7.00.00.184 or later, iDRAC9 on 15G/16G systems to 7.30.10.50 or later, and iDRAC10 on 17th-generation systems to 1.30.30.50 or later. Until patched, restrict iDRAC access to dedicated management networks or VPN rather than the public internet, and review which high-privileged accounts could reach the controller. Inventory internet-facing iDRAC endpoints (management web UIs) and prioritize those patches first.
| Dell iDRAC9 (PowerEdge 14th generation) | prior to 7.00.00.184 |
| Dell iDRAC9 (PowerEdge 15G/16G) | prior to 7.30.10.50 |
| Dell iDRAC10 (PowerEdge 17th generation) | prior to 1.30.30.50 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.