SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-23855

HIGH · CVSS 7.2 EPSS 0.93% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Dell iDRAC9, 14G, 15G/16G, and 17G versions prior to specified releases are vulnerable to an OS command injection flaw, allowing high-privileged remote attackers to execute arbitrary commands on the affected systems. This vulnerability poses a significant risk as it could lead to unauthorized access and control over critical infrastructure. Organizations utilizing these Dell iDRAC versions should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-23855
Severity
HIGH
CVSS
7.2
EPSS
0.93%

Original NVD Description

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.