Junglewise Threat Intelligence

CVE-2026-79645: Dell Secure Connect Gateway missing authentication in critical function

CVE-2026-79645 · Severity: high · CVSS 8.2 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access and VPN solution used by enterprises to securely connect users to corporate networks. A missing authentication vulnerability allows unauthenticated attackers to bypass security controls and gain unauthorized access to sensitive gateway functions, potentially compromising the security of all connected users and internal systems.

Technical details

The vulnerability is a missing authentication for critical function (CWE-306) affecting Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively. An unauthenticated attacker with network access can exploit this vulnerability to bypass authentication controls and access critical functions without valid credentials. The attack requires no user interaction, complex prerequisites, or elevated privileges. This enables unauthorized access to the gateway and potentially sensitive operations. Dell has released patched versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to remediate the issue.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Vulnerability published in NVD
  • 2026-09-07: advisory: Dell DSA-2026-382 security update released

References

Related threats