CVE-2026-23855
Last modified
CVE-2026-23855 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Dell | iDRAC9 | < 7.30.10.50 or later; < 7.00.00.184 or later |
| Dell | iDRAC10 | < 1.30.30.50 or later |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-23855?
How severe is CVE-2026-23855?
How do I fix CVE-2026-23855?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23849File Browser provides a file managing interface within a spe…5.3
- CVE-2026-2385The The Plus Addons for Elementor – Addons for Elementor, Pa…5.3
- CVE-2026-23850SiYuan is a personal knowledge management system. In version…7.5
- CVE-2026-23851SiYuan is a personal knowledge management system. Versions p…6.5
- CVE-2026-23852SiYuan is a personal knowledge management system. Versions p…9.6
- CVE-2026-23853Dell PowerProtect Data Domain with Data Domain Operating Sys…8.4
- CVE-2026-23856Dell iDRAC Service Module (iSM) for Windows, versions prior …7.8
- CVE-2026-23857Dell Update Package (DUP) Framework, versions 23.12.00 throu…8.2
- CVE-2026-23858Dell Wyse Management Suite, versions prior to WMS 5.5, conta…5.4
- CVE-2026-23859Dell Wyse Management Suite, versions prior to WMS 5.5, conta…2.7
- CVE-2026-2386The The Plus Addons for Elementor – Addons for Elementor, Pa…4.3
- CVE-2026-23861Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contai…5.4
Are you affected by CVE-2026-23855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
