---
id: CVE-2026-23855
title: >-
  Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to
  7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an
  Improper Neutralization of Special Elements used in an OS Command ('OS Command
  Injection…
summary: >-
  Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to
  7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an
  Improper Neutralization of Special Elements used in an OS Command ('OS Command
  Injection…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-78
vendor: Dell
product: iDRAC9
affected:
  - iDRAC9 < 7.30.10.50 or later
  - iDRAC9 < 7.00.00.184 or later
  - iDRAC10 < 1.30.30.50 or later
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T00:00:00+00:00'
published: '2026-09-09'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T03:56:14.162Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23855'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000504998/dsa-2026-392-security-update-for-dell-idrac9-and-idrac10-vulnerability
tags:
  - cve.org
epss: 0.00931
epssPercentile: 0.58945
ingestedAt: '2026-09-11T16:45:47.926Z'
---

## Overview

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.

## Affected

- `iDRAC9 < 7.30.10.50 or later`
- `iDRAC9 < 7.00.00.184 or later`
- `iDRAC10 < 1.30.30.50 or later`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
