Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used to provide VPN-like connectivity for hybrid workforces. An improper certificate validation vulnerability allows unauthenticated remote attackers to bypass security controls and gain unauthorized access to the system, potentially compromising customer data and business operations.
Technical details
CVE-2026-78494 is an improper certificate validation vulnerability in Dell SCG 5.0 that allows unauthenticated remote attackers to bypass SSL/TLS certificate verification controls. The vulnerability exists because the application fails to properly validate server certificates during secure communications, enabling attackers to intercept, spoof, or manipulate encrypted connections without detection. An attacker with network access can exploit this flaw to establish unauthorized connections and gain access to sensitive functions. The vulnerability affects both the SCG Appliance (versions prior to 5.36.00.16) and SCG Application (versions prior to 5.36.00.00). Dell has released patched versions that implement proper certificate validation to remediate this issue.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed