Junglewise Threat Intelligence

CVE-2026-78482: Dell Secure Connect Gateway OS command injection in SCG 5.0

CVE-2026-78482 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a virtual appliance used to provide secure remote access and connectivity for enterprise networks. Versions prior to 5.36.00.16 contain an OS command injection vulnerability that allows a low-privileged attacker with local access to execute arbitrary system commands, potentially leading to full system compromise and unauthorized access to sensitive network resources.

Technical details

CVE-2026-78482 is an OS Command Injection (CWE-78) vulnerability in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The vulnerability exists due to improper neutralization of special elements in OS commands, allowing an attacker with local access and low privileges to inject and execute arbitrary commands. The attack vector is local with low privilege requirements. Successful exploitation enables command execution with the privileges of the affected application, potentially leading to system compromise. The fix is available in version 5.36.00.16 for the appliance and 5.36.00.00 for the application.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats