Junglewise Threat Intelligence

CVE-2026-63695: Dell SmartFabric OS10 session fixation vulnerability

CVE-2026-63695 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Dell SmartFabric OS10 is network operating system software that manages switching and fabric functions in data center networks. A session fixation flaw in versions before 10.6.1.3 allows an unauthenticated remote attacker to steal user sessions, potentially gaining unauthorized access to network devices and sensitive operational controls without needing valid credentials.

Technical details

The vulnerability is a session fixation flaw in Dell SmartFabric OS10 prior to version 10.6.1.3. An unauthenticated remote attacker can exploit this weakness to hijack legitimate user sessions and gain unauthorized access to the system. The attack requires network reachability to the affected device but no prior authentication or user interaction. Successful exploitation results in session theft, allowing attackers to assume the privileges of the compromised user. A patch is available in version 10.6.1.3 and later.

Affected products

  • Dell SmartFabric OS10 prior to 10.6.1.3

Timeline

  • 2026-09-15: disclosed

References

Related threats