Junglewise Threat Intelligence

CVE-2026-79971: Dell Secure Connect Gateway improper input sanitization XSS

CVE-2026-79971 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a VPN/remote access appliance used by enterprises to secure and manage connectivity. Versions prior to 5.36.00.16 contain an improper sanitization vulnerability that allows unauthenticated attackers to inject malicious scripts, potentially compromising user sessions, stealing credentials, or gaining unauthorized system access.

Technical details

CVE-2026-79971 is a script injection vulnerability caused by improper sanitization of custom special characters in Dell SCG 5.0 Appliance (versions before 5.36.00.16) and Application (versions before 5.36.00.00). The vulnerability is network-accessible and requires no authentication or user interaction. An attacker can craft malicious payloads with special characters to bypass input validation and inject scripts into the application, leading to cross-site scripting (XSS) or similar injection attacks. The patched versions are available from Dell.

Affected products

  • Dell Secure Connect Gateway Application before 5.36.00.00
  • Dell Secure Connect Gateway Appliance before 5.36.00.16

Timeline

  • 2026-09-09: disclosed: CVE-2026-79971 disclosed
  • patched: Fixed in SCG 5.0 Application 5.36.00.00 and Appliance 5.36.00.16

References

Related threats