Junglewise Threat Intelligence

CVE-2026-79946: Dell SCG 5.0 cross-site scripting in alternate XSS syntax

CVE-2026-79946 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used to protect corporate network connectivity. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain an improper neutralization vulnerability that allows an unauthenticated remote attacker to inject malicious scripts, potentially compromising user sessions or stealing sensitive data.

Technical details

This vulnerability is an Improper Neutralization of Alternate XSS Syntax (CWE-80), which arises when the application fails to properly sanitize user-supplied input before rendering it in a web context. An unauthenticated attacker with network access to the SCG appliance or application can craft and deliver payloads using alternate XSS syntax that bypass the application's input filters. The attack requires no special privileges or user interaction. Successful exploitation allows arbitrary JavaScript execution in the victim's browser, potentially leading to session hijacking, credential theft, or further network compromise. Patches are available in SCG 5.36.00.16 (appliance) and 5.36.00.00 (application).

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats