Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance and application used to manage secure connections to corporate networks. This vulnerability allows an unauthenticated attacker to bypass authentication protections by submitting excessive login attempts without restriction, potentially leading to account compromise or client-side request forgery attacks.
Technical details
CVE-2026-78490 is an improper restriction of excessive authentication attempts vulnerability in Dell SCG 5.0 Appliance (versions prior to 5.36.00.16) and SCG 5.0 Application (versions prior to 5.36.00.00). The vulnerability allows an unauthenticated remote attacker to bypass rate-limiting or account lockout mechanisms that would normally protect against brute-force attacks. This lack of restriction on repeated authentication attempts enables attackers to perform credential stuffing or brute-force attacks with impunity. The advisory indicates the vulnerability can lead to client-side request forgery. Dell recommends upgrading to patched versions 5.36.00.16 (Appliance) or 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed