Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and connectivity for enterprise environments. CVE-2026-61410 is a missing authorization vulnerability that allows unauthenticated attackers with network access to execute arbitrary commands remotely by bypassing authentication controls, potentially giving attackers full control of the system and access to sensitive data flowing through it.
Technical details
This vulnerability is a missing authorization flaw in Dell SCG 5.0 that allows unauthenticated remote code execution. An attacker can send a specially crafted request to the application to bypass intended restrictions and execute commands on the target system without authentication. The vulnerability affects Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The attack vector is network-based with no prerequisites (no authentication required, no user interaction), making it trivially exploitable. Dell has released patched versions and recommends immediate upgrade.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed