Executive brief
Dell iDRAC is a remote management interface that allows IT administrators to monitor and control physical servers out-of-band. A vulnerability in iDRAC permits high-privileged attackers with network access to inject arbitrary OS commands, potentially leading to complete compromise of the managed server. An attacker could gain unauthorized control over server hardware, access sensitive data, or disrupt critical business operations.
Technical details
The vulnerability is an OS command injection (CWE-78) in Dell iDRAC9 (14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50) and iDRAC10 (17G versions prior to 1.30.30.50). It requires high privilege authentication and remote network access, but allows an authenticated attacker to execute arbitrary OS commands on the managed server. The attack is straightforward with no additional complexity (AC:L), and impacts confidentiality, integrity, and availability. Patches are available: iDRAC9 14G should update to 7.00.00.184 or later, iDRAC9 15G/16G to 7.30.10.50 or later, and iDRAC10 17G to 1.30.30.50 or later.
Affected products
- Dell iDRAC9 14G versions prior to 7.00.00.184; 15G/16G versions prior to 7.30.10.50
- Dell iDRAC10 17G versions prior to 1.30.30.50
Timeline
- 2026-09-09: disclosed: CVE-2026-23855 published
- 2026-09-03: patched: Dell security advisory DSA-2026-392 issued with remediation versions