Junglewise Threat Intelligence

CVE-2026-80054: Dell Secure Connect Gateway incorrect permission assignment in critical resource

CVE-2026-80054 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and VPN connectivity. A flaw in permission assignments allows a low-privileged local attacker to gain unauthorized access to critical resources, potentially compromising data confidentiality and the integrity of the gateway itself.

Technical details

CVE-2026-80054 is an Incorrect Permission Assignment for Critical Resource vulnerability (CWE-732) in Dell SCG versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). The vulnerability allows a low-privileged attacker with local access to the system to access or modify critical resources that should be restricted to privileged users. This represents a privilege escalation vector on the appliance or application host. The attack requires local access, meaning the attacker must have a valid local account or shell access to the system. Patches are available in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Updates available for version 5.36.00.16 (Appliance) and 5.36.00.00 (Application)

References

Related threats