Junglewise Threat Intelligence

CVE-2026-79641: Dell Secure Connect Gateway OS command injection vulnerability

CVE-2026-79641 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is an appliance and application used to provide secure remote access to corporate networks. A low-privileged attacker with network access can inject arbitrary operating system commands through improper input validation, gaining elevated privileges on the gateway system and potentially compromising all connected systems.

Technical details

The vulnerability is an OS command injection (CWE-78) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00, stemming from improper neutralization of special characters in user-controlled input passed to OS commands. A low-privileged authenticated or remote attacker can exploit this by crafting malicious input containing shell metacharacters to execute arbitrary commands with the privileges of the vulnerable application process. The attack vector is network-based with low complexity. Patches are available in SCG 5.0 version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats