Junglewise Threat Intelligence

CVE-2026-79643: Dell Secure Connect Gateway Use of Incorrect Operator privilege bypass

CVE-2026-79643 · Severity: high · CVSS 7.3 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a virtual appliance used to provide secure remote access to networks. An unauthenticated attacker with network access could exploit a logic error in access control to bypass authentication and gain unauthorized administrative access to the system without credentials.

Technical details

CVE-2026-79643 is a Use of Incorrect Operator vulnerability in the authentication or authorization logic of Dell SCG 5.0. An unauthenticated attacker with network access can exploit this vulnerability to potentially gain unauthorized access to the appliance. The vulnerability likely stems from a conditional logic error (using an incorrect operator such as OR instead of AND) in a security-critical function that validates user permissions or authentication state. The attack requires only network reachability to the appliance and no prior authentication. If successfully exploited, an attacker could obtain administrative access and control over the system.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed

References

Related threats