Skip to content
Dell TechnologiesCVE-2026-23855

Dell Technologies iDRAC10: command injection

High7.2CVE-2026-23855 · Published Sep 9, 2026 · updated Sep 11, 2026

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
iDRAC10
Product
< 1.30.30.50 or later1.30.30.50 or later
iDRAC9
Product
< 7.30.10.50 or later7.30.10.50 or later
< 7.00.00.184 or later7.00.00.184 or later
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies PowerScale OneFS: command injection
Medium6.7Sep 9
Dell Technologies PowerScale OneFS: denial of service
Medium5.4Sep 9
Dell Technologies PowerScale OneFS: improper authorization
Low3.5Sep 9
Dell Technologies Secure Connect Gateway 5.0: command injection
Medium5.3Sep 9
Dell Technologies Secure Connect Gateway 5.0: excessive privileges
Low3.4Sep 9
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0...
Low3.4Sep 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.