Dell iDRAC9 < 7.00.00.174 / 7.10.90.00 Information Disclosure (DSA-2026-113)

medium Nessus Plugin ID 303190

Synopsis

The remote Dell iDRAC9 is affected by an information disclosure vulnerability.

Description

The version of Dell iDRAC9 installed on the remote host is affected by an information disclosure vulnerability as referenced in the DSA-2026-113 advisory.

- Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. (CVE-2026-26948)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dell iDRAC9 version 7.00.00.174 (14G) or 7.10.90.00 (15G/16G) or later.

See Also

https://www.dell.com/support/kbdoc/en-us/000434533/dsa-2026-113

Plugin Details

Severity: Medium

ID: 303190

File Name: drac_dsa-2026-113.nasl

Version: 1.1

Type: remote

Family: CGI abuses

Published: 3/20/2026

Updated: 3/20/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.1

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:N/A:N

CVSS Score Source: CVE-2026-26948

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/a:dell:emc_idrac9

Required KB Items: installed_sw/iDRAC

Patch Publication Date: 3/17/2026

Vulnerability Publication Date: 3/17/2026

Reference Information

CVE: CVE-2026-26948

IAVB: 2026-B-0070