CVE-2026-23856

7.8

Dell · iDRAC Service Module (iSM)

Dell iDRAC Service Module contains an improper access control vulnerability that allows a local, low-privileged attacker to achieve privilege escalation.

Executive summary

Dell iDRAC Service Module versions prior to 6.0.3.1 on Windows and 5.4.1.1 on Linux are vulnerable to local privilege escalation, posing a significant risk to system integrity.

Vulnerability

This is an improper access control vulnerability (CWE-284) that allows a local attacker with low privileges to escalate their permissions, potentially gaining full control over the host system.

Business impact

Successful exploitation of this vulnerability allows an authenticated local user to elevate privileges, potentially resulting in full system compromise, unauthorized data access, and loss of server availability. With a CVSS score of 7.8, this flaw is categorized as High severity and represents a significant risk to the security posture of affected Dell server environments.

Remediation

Immediate Action: Update the Dell iDRAC Service Module to version 6.0.3.1 or later for Windows, or 5.4.1.1 or later for Linux, as detailed in the official Dell security advisory DSA-2026-077.

Proactive Monitoring: Monitor system logs for unauthorized attempts to access administrative functions or unexpected privilege changes by low-privileged user accounts.

Compensating Controls: Restrict local system access to authorized personnel only and ensure the Principle of Least Privilege is strictly enforced for all local user accounts to prevent unauthorized users from reaching the vulnerable interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the High severity rating and the potential for a complete system takeover, organizations must prioritize the deployment of the vendor-provided patches. IT administrators should verify their current version of the iDRAC Service Module across all server assets and schedule maintenance windows to apply the necessary updates immediately.

More Dell CVEs

Sources