Junglewise Threat Intelligence

CVE-2026-79941: Dell Secure Connect Gateway command injection

CVE-2026-79941 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access appliance and application used to securely connect users to corporate resources. A command injection vulnerability in versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) allows unauthenticated attackers to inject arbitrary commands, potentially leading to script execution and full system compromise.

Technical details

This vulnerability is an improper neutralization of special elements in command input (CWE-78: Command Injection). An unauthenticated attacker with network access can exploit this flaw by sending specially crafted input to the application, which fails to properly sanitize command parameters before execution. The attack vector is network-based with no authentication required and no user interaction needed. Successful exploitation allows script injection, which can lead to remote code execution depending on the privilege context. Patches are available in SCG 5.0 Appliance 5.36.00.16 and later, and SCG 5.0 Application 5.36.00.00 and later.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: Public disclosure via NVD and Dell advisory DSA-2026-382
  • 2026-09-09: patched: Patches available: SCG 5.0 Appliance 5.36.00.16+, SCG 5.0 Application 5.36.00.00+

References

Related threats