Junglewise Threat Intelligence

CVE-2026-79944: Dell Secure Connect Gateway least privilege violation

CVE-2026-79944 · Severity: low · CVSS 3.4 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a secure network connectivity appliance used to manage remote access and VPN tunnels for enterprise networks. A least privilege violation in SCG versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) could allow a high-privileged local attacker to gain unauthorized access beyond their assigned permissions, potentially leading to system compromise or lateral movement within the network.

Technical details

CVE-2026-79944 is a least privilege violation in Dell SCG affecting versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application). A high-privileged attacker with local access to the system can exploit this vulnerability to escalate or exceed their intended privilege level. The attack requires local access and elevated privileges as a precondition. The vulnerability allows unauthorized access beyond the attacker's assigned role or permission scope. Customers should upgrade to SCG 5.36.00.16 (appliance) or 5.36.00.00 (application) or later to remediate this issue.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats