Junglewise Threat Intelligence

CVE-2026-79640: Dell Secure Connect Gateway SQL injection vulnerability

CVE-2026-79640 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) 5.0 is a remote access appliance used to control secure network connectivity and access. A low-privileged attacker with remote access can inject malicious SQL commands into the application, potentially bypassing authentication controls and gaining unauthorized access to sensitive system data or functions.

Technical details

The vulnerability is a SQL injection flaw in Dell SCG 5.0 Appliance (versions before 5.36.00.16) and Application (versions before 5.36.00.00) that fails to properly neutralize special SQL elements in user-supplied input. A low-privileged attacker with remote network access can craft specially formatted requests containing SQL metacharacters to manipulate database queries, potentially allowing unauthorized data access or authentication bypass. No user interaction is required. Dell has released patches in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to remediate this issue.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-79640 published
  • 2026-09-09: patched: Patch released in SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00

References

Related threats