Description
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.
Published: 2026-08-26
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell iDRAC9 firmware versions before 7.00.00.182 (14G) or before 7.20.30.50 (15G/16G) contain an Improper Access Control flaw. An unauthenticated attacker who can reach the iDRAC interface over the network can exploit this weakness and obtain data that should be restricted to authorized personnel. The flaw does not grant full system control but can expose sensitive configuration, logs, or credentials stored within iDRAC. Affected systems include Dell iDRAC9 14G releases earlier than 7.00.00.182 and 15G or 16G releases earlier than 7.20.30.50. These firmware versions are distributed across many Dell servers that use remote management. The CVSS score of 5.9 places the vulnerability in the medium severity range. Because the EPSS metric is not available, the likelihood of exploitation cannot be quantified from the data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote unauthenticated access to the iDRAC web interface, as the description specifies an "unauthenticated attacker with remote access".

Affected Systems

Dell iDRAC9 14G firmware prior to 7.00.00.182 and Dell iDRAC9 15G/16G firmware prior to 7.20.30.50.

Risk and Exploitability

A moderate severity flaw that allows an attacker to read protected data over the network. The lack of an EPSS rating and KEV listing suggests limited known exploitation, but the remote nature and lack of authentication make it a meaningful risk in exposed environments.

Generated by OpenCVE AI on August 26, 2026 at 19:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the iDRAC firmware to the latest version (at least 7.00.00.182 for 14G or 7.20.30.50 for 15G/16G).
  • Ensure that iDRAC access is restricted to trusted network segments and block direct internet exposure.
  • Configure iDRAC to require authenticated access and disable or change default credentials if still present.

Generated by OpenCVE AI on August 26, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell idrac9
Vendors & Products Dell
Dell idrac9

Wed, 26 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Data Access via Improper Access Control in Dell iDRAC9

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T19:46:27.415Z

Reserved: 2026-08-25T15:04:54.600Z

Link: CVE-2026-79940

cve-icon Vulnrichment

Updated: 2026-08-26T19:46:21.761Z

cve-icon NVD

Status : Received

Published: 2026-08-26T19:17:19.213

Modified: 2026-08-26T20:18:14.380

Link: CVE-2026-79940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:00:11Z

Weaknesses