Junglewise Threat Intelligence

CVE-2026-79741: Dell Secure Connect Gateway command injection vulnerability

CVE-2026-79741 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a critical appliance and application used to manage remote secure access and network connectivity for enterprises. A command injection vulnerability in versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) allows unauthenticated remote attackers to execute arbitrary commands, potentially compromising the entire gateway and all systems it protects.

Technical details

This is a command injection vulnerability (CWE-78) in Dell Secure Connect Gateway that fails to properly neutralize special elements in user-supplied input before passing it to shell commands. An unauthenticated attacker with network access can send specially crafted requests containing shell metacharacters to exploit this flaw, leading to script injection and arbitrary command execution on the appliance. No authentication, user interaction, or special privileges are required for exploitation. Dell has released patches addressing this issue in SCG 5.0 Appliance 5.36.00.16 and SCG 5.0 Application 5.36.00.00, which should be applied immediately.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00

References

Related threats