# CVE-2026-23855

## Summary

- **CVE ID:** CVE-2026-23855
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-78
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.

## Affected Products

- Dell — iDRAC9 (0)
- Dell — iDRAC10 (0)

## References

- [CNA](https://www.dell.com/support/kbdoc/en-us/000504998/dsa-2026-392-security-update-for-dell-idrac9-and-idrac10-vulnerability)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._