Description
Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.
Published: 2026-09-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability stems from improper neutralization of special elements used in OS command strings, enabling OS Command Injection on Dell iDRAC9 and iDRAC10. An attacker with high privileges and remote access could inject arbitrary commands, potentially executing code with the privileges of the iDRAC process and compromising firmware and host systems. The weakness is catalogued as CWE-78.

Affected Systems

Affected devices include Dell iDRAC9 for 14G versions earlier than 7.00.00.184, 15G/16G versions earlier than 7.30.10.50, and Dell iDRAC10 for 17G versions earlier than 1.30.30.50. All affected firmware revisions are from Dell.

Risk and Exploitability

The CVSS score of 7.2 indicates substantial risk, and the EPSS score is not available, with no listing in the KEV catalog. Because the problem requires high privileged remote access, the likelihood of exploitation depends on attacker presence in the network; no public exploit has been reported, yet the possibility for a targeted breach remains significant.

Generated by OpenCVE AI on September 9, 2026 at 18:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell firmware update to bring iDRAC9 to version 7.00.00.184 or newer, iDRAC9 15G/16G to 7.30.10.50 or newer, or iDRAC10 to 1.30.30.50 or newer as described in the Dell advisory.
  • Restrict remote access to iDRAC interfaces to trusted networks only, using firewall rules or VLAN segmentation.
  • Enforce strong authentication policies and disable default credentials on all iDRAC devices.

Generated by OpenCVE AI on September 9, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell idrac10
Dell idrac9
Vendors & Products Dell
Dell idrac10
Dell idrac9

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection via Improper Neutralization in Dell iDRAC9 and iDRAC10

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T03:56:14.162Z

Reserved: 2026-01-16T18:05:07.319Z

Link: CVE-2026-23855

cve-icon Vulnrichment

Updated: 2026-09-09T18:11:27.775Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T17:17:19.837

Modified: 2026-09-11T04:17:40.123

Link: CVE-2026-23855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:00:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')