Dell SmartFabric OS10 <10.6.1.3: DCOIC Remote Code Exec
CVE-2026-63696 Published on September 15, 2026

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-63696 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
HIGH
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.


Products Associated with CVE-2026-63696

Want to know whenever a new CVE is published for Dell Smartfabric Os10? stack.watch will email you.

 

Affected Versions

Dell SmartFabric OS10 Software: