Junglewise Threat Intelligence

CVE-2026-79961: Dell Secure Connect Gateway missing authentication for critical function

CVE-2026-79961 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access and VPN appliance used to secure connections to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) lack proper authentication controls on critical functions, allowing unauthenticated remote attackers to gain unauthorized access without valid credentials.

Technical details

This vulnerability is a missing authentication control (CWE-306) affecting critical functions in Dell SCG 5.0. An unauthenticated attacker with network access can exploit this by directly accessing protected functions without providing credentials. The vulnerability has no preconditions—no authentication, special privileges, or user interaction is required. An attacker can achieve unauthorized access to the system. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and SCG 5.0 Application version 5.36.00.00 or later; customers should upgrade immediately.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-79961 published

References

Related threats