Junglewise Threat Intelligence

CVE-2026-78480: Dell Secure Connect Gateway missing authentication in critical function

CVE-2026-78480 · Severity: high · CVSS 7.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network security appliance and application used to manage secure remote access and virtual private networking for enterprises. Versions before 5.36.00.16 (appliance) and 5.36.00.00 (application) are missing authentication checks on critical functions, allowing attackers to bypass login requirements and gain unauthorized administrative access to the system without credentials.

Technical details

This vulnerability is a missing authentication control on critical functions in Dell SCG, classified as CWE-306. An unauthenticated attacker with network access can exploit this by sending requests directly to protected endpoints that lack proper authentication verification. The vulnerability allows unauthorized access to administrative or sensitive functions without requiring valid credentials. The affected versions are Dell SCG 5.0 Appliance prior to 5.36.00.16 and Dell SCG 5.0 Application prior to 5.36.00.00. Dell has released patches to address this issue and recommends immediate upgrade.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed

References

Related threats