CVE-2026-23856: Dell Idrac Service Module
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected products
- Dell Idrac Service Module: before 5.4.1.1 (fixed in 5.4.1.1); before 6.0.3.1 (fixed in 6.0.3.1)
- Dell Idrac Service Module For Linux: before 5.4.1.1 (fixed in 5.4.1.1)
Published 2026-02-12. Last modified 2026-06-17.