Junglewise Threat Intelligence

CVE-2026-79740: Dell Secure Connect Gateway hard-coded credentials vulnerability

CVE-2026-79740 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network appliance used to manage remote access and secure connections for enterprise users. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain hard-coded credentials that an unauthenticated attacker can exploit to gain unauthorized access to the system, potentially exposing sensitive configuration data and enabling further compromise of the network.

Technical details

The vulnerability is a use of hard-coded credentials issue in Dell SCG 5.0, allowing unauthenticated attackers with remote network access to authenticate without valid user credentials. By leveraging the embedded credentials, an attacker can bypass authentication controls and access administrative functions. The affected versions are Appliance prior to 5.36.00.16 and Application prior to 5.36.00.00. Patches are available in the indicated versions. This is part of a broader security advisory (DSA-2026-382) addressing multiple vulnerabilities in the same product.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16 and 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: Published in NVD
  • 2026-09-09: advisory: Dell DSA-2026-382 security update issued

References

Related threats