Junglewise Threat Intelligence

CVE-2026-78485: Dell Secure Connect Gateway path traversal vulnerability

CVE-2026-78485 · Severity: high · CVSS 7.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a virtual appliance used to provide secure remote access to corporate networks. Versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain a path traversal flaw that allows unauthenticated remote attackers to access files outside intended directories, potentially exposing sensitive configuration data, credentials, or system files without authentication.

Technical details

The vulnerability is a path traversal (CWE-126: Improper Limitation of a Pathname to a Restricted Directory) flaw in Dell SCG 5.0 that fails to properly validate and sanitize file path inputs. An unauthenticated attacker with network access can exploit this by sending specially crafted requests containing traversal sequences (e.g., "../") to bypass directory restrictions and read arbitrary files. No authentication or special privileges are required to trigger the vulnerability. Successful exploitation leads to unauthorized information disclosure of sensitive files on the affected system. Patches are available in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application) and later.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: Published by NVD and Dell Security Advisory DSA-2026-382

References

Related threats