Junglewise Threat Intelligence

CVE-2026-79689: Dell Secure Connect Gateway OS command injection

CVE-2026-79689 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access appliance used by enterprises to enable secure connections for distributed workforces. Versions prior to 5.36.00.16 contain a command injection vulnerability that allows unauthenticated attackers to inject arbitrary OS commands, potentially leading to full system compromise and unauthorized data access.

Technical details

The vulnerability is an Improper Neutralization of Special Elements used in an OS Command (CWE-78, OS Command Injection). An unauthenticated attacker with network access can send specially crafted requests to inject arbitrary OS commands into the SCG application. No authentication is required to exploit this vulnerability. Successful exploitation results in script/command injection on the affected system, allowing arbitrary code execution with the privileges of the SCG service. The vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Patches are available from Dell via security update DSA-2026-382.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: Published on NVD
  • 2026-09-09: advisory: Dell security advisory DSA-2026-382 released

References

Related threats