Junglewise Threat Intelligence

CVE-2026-79945: Dell Secure Connect Gateway OS command injection in local process

CVE-2026-79945 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network security appliance used to manage secure remote access and connectivity. A local attacker with low privileges can execute arbitrary operating system commands on the appliance due to improper input validation, potentially gaining full control of the system and compromising all data and connectivity it manages.

Technical details

This is an OS command injection vulnerability (CWE-78) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The vulnerability exists due to improper neutralization of special elements used in OS commands, allowing unsanitized user input to be passed to system command execution functions. Attack requires local access and low privilege level; an attacker can craft a malicious input that breaks out of the intended command context and executes arbitrary shell commands. Successful exploitation allows command execution with the privileges of the affected process. Dell has released patches in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: SCG Appliance 5.36.00.16, SCG Application 5.36.00.00

References

Related threats