Executive brief
Dell Secure Connect Gateway (SCG) is a virtual appliance used to provide secure remote access and connectivity for enterprise networks. Versions prior to 5.36.00.16 contain an OS command injection vulnerability that allows a low-privileged attacker with local access to execute arbitrary system commands, potentially leading to full system compromise and unauthorized access to sensitive network resources.
Technical details
CVE-2026-78482 is an OS Command Injection (CWE-78) vulnerability in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The vulnerability exists due to improper neutralization of special elements in OS commands, allowing an attacker with local access and low privileges to inject and execute arbitrary commands. The attack vector is local with low privilege requirements. Successful exploitation enables command execution with the privileges of the affected application, potentially leading to system compromise. The fix is available in version 5.36.00.16 for the appliance and 5.36.00.00 for the application.
Affected products
- Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
- Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed