CVE-2026-26945
Received
Received - Intake
Process Control Vulnerability in Dell iDRAC Allows Code Execution
Publication date: 2026-03-18
Last updated on: 2026-03-18
Assigner: Dell
Description
Description
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | integrated_dell_remote_access_controller_9 | to 7.00.00.181 (exc) |
| dell | integrated_dell_remote_access_controller_14g | to 7.00.00.181 (exc) |
| dell | integrated_dell_remote_access_controller_15g | to 7.20.10.50 (exc) |
| dell | integrated_dell_remote_access_controller_16g | to 7.20.10.50 (exc) |
| dell | integrated_dell_remote_access_controller_10 | to 1.20.25.00 (exc) |
| dell | integrated_dell_remote_access_controller_17g | to 1.20.25.00 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-114 | Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker. |