Junglewise Threat Intelligence

CVE-2026-79950: Dell Secure Connect Gateway hard-coded credentials vulnerability

CVE-2026-79950 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access appliance and application used to establish secure connections to corporate networks. Versions prior to 5.36 contain hard-coded credentials that allow unauthenticated attackers with network access to gain unauthorized access to the system, potentially leading to exposure of sensitive data and network compromise.

Technical details

The vulnerability is a use of hard-coded credentials issue in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can exploit embedded default credentials to gain unauthorized access to the affected system. This is a network-reachable attack requiring no authentication or user interaction. The primary impact is information exposure and potential system compromise through credential-based authentication bypass. Dell has released patches addressing this vulnerability.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-79950 published

References

Related threats