Junglewise Threat Intelligence

CVE-2026-78493: Dell SCG 5.0 OS command injection in local access

CVE-2026-78493 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network security appliance and application used to establish secure remote access connections. A local attacker with low privileges can exploit an OS command injection flaw to execute arbitrary commands with elevated access, potentially compromising system security and availability.

Technical details

CVE-2026-78493 is an OS command injection vulnerability (CWE-78) in Dell SCG 5.0 Application and Appliance editions that stems from improper neutralization of special characters in OS commands. The vulnerability requires local access and low-level privileges to exploit, allowing an attacker to inject and execute arbitrary system commands. This could lead to full system compromise, data theft, or service disruption. The fix is available in Dell SCG 5.0 Appliance version 5.36.00.16 and Application version 5.36.00.00 or later.

Affected products

  • Dell SCG 5.0 Appliance prior to 5.36.00.16
  • Dell SCG 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: advisory: Dell DSA-2026-382 published

References