Executive brief
Dell Secure Connect Gateway (SCG) is a network security appliance and application that provides secure remote access. CVE-2026-78488 is an OS command injection vulnerability that allows a low-privileged remote attacker to execute arbitrary commands on affected systems. Successful exploitation could lead to complete system compromise, data breach, or lateral movement within the network.
Technical details
The vulnerability is an improper neutralization of special elements used in OS commands (CWE-78: OS Command Injection). A low-privileged attacker with remote network access can exploit this flaw by sending specially crafted input that is not properly sanitized before being passed to system commands. The vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Successful exploitation results in arbitrary command execution in the context of the application, potentially leading to system compromise. Dell has released patched versions that sanitize command inputs appropriately.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed