Executive brief
Dell iDRAC9 is a remote management interface that allows administrators to monitor and control servers remotely. This vulnerability allows an unauthenticated attacker with network access to bypass access controls and gain unauthorized access to sensitive management data on affected Dell servers, potentially exposing configuration details, system logs, and other confidential information.
Technical details
The vulnerability is an improper access control flaw in Dell iDRAC9 (versions prior to 7.00.00.182 for 14G servers and prior to 7.20.30.50 for 15G/16G servers). An unauthenticated, remote attacker can exploit this vulnerability without user interaction to bypass authentication controls. The attack requires network access to the iDRAC interface but has high complexity (AC:H per CVSS vector). Successful exploitation results in unauthorized disclosure of sensitive data (integrity impact noted in CVSS). Patches are available: version 7.00.00.182 or later for 14G, and version 7.20.30.50 or later for 15G/16G.
Affected products
- Dell iDRAC9 14G versions prior to 7.00.00.182; 15G/16G versions prior to 7.20.30.50
Timeline
- 2026-08-26: disclosed: Published on NVD
- 2026-08-25: advisory: Dell DSA-2026-374 initial release