Junglewise Threat Intelligence

CVE-2026-79974: Dell Secure Connect Gateway improper authentication vulnerability

CVE-2026-79974 · Severity: medium · CVSS 6.4 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access appliance and application that manages secure connections for enterprise networks. An improper authentication flaw allows a low-privileged remote attacker to bypass authentication controls and gain unauthorized access to the system. This could enable attackers to take control of critical remote access infrastructure and compromise network security.

Technical details

CVE-2026-79974 is an improper authentication vulnerability in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. A low-privileged attacker with remote network access can exploit this flaw to bypass authentication mechanisms and gain unauthorized access. The vulnerability allows attackers with network reachability to the affected system to escalate privileges without proper credential validation. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and SCG 5.0 Application version 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-79974 disclosed

References

Related threats