Junglewise Threat Intelligence

CVE-2026-79728: Dell Secure Connect Gateway relative path traversal

CVE-2026-79728 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network appliance and application that securely connects remote systems to corporate networks. A relative path traversal vulnerability in SCG allows an unauthenticated attacker with network access to read arbitrary files from the system's filesystem, potentially exposing sensitive configuration data, credentials, and other protected information.

Technical details

The vulnerability is a relative path traversal flaw in Dell SCG 5.0 versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). An unauthenticated attacker can craft requests using path traversal sequences (e.g., "../" or equivalent relative path manipulation) to access files outside the intended directory structure. No authentication is required; the attack is entirely network-reachable. Successful exploitation grants an attacker arbitrary filesystem read access, enabling them to retrieve sensitive files including credentials, configuration data, and other protected information. The vendor has released patches (5.36.00.16 for Appliance and 5.36.00.00 for Application).

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: Vulnerability published via Dell DSA-2026-382

References

Related threats