Junglewise Threat Intelligence

CVE-2026-79947: Dell Secure Connect Gateway OS command injection vulnerability

CVE-2026-79947 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a network appliance and application used to enable secure remote access and VPN connectivity for enterprises. A low-privileged local attacker can inject arbitrary OS commands through improper input handling, potentially executing malicious code with elevated privileges and compromising the entire gateway infrastructure.

Technical details

This vulnerability is an OS command injection (CWE-78) flaw in Dell Secure Connect Gateway's handling of user input. A low-privileged local attacker with access to the system can craft specially crafted input that is not properly neutralized before being passed to an OS command interpreter, allowing arbitrary command execution. The attack vector is local and requires low privileges but no user interaction. Successful exploitation allows script injection and potential lateral movement or privilege escalation. Patches are available: Appliance versions 5.36.00.16 and later, Application versions 5.36.00.00 and later.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats