Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and VPN connectivity. A flaw in permission assignments allows a low-privileged local attacker to gain unauthorized access to critical resources, potentially compromising data confidentiality and the integrity of the gateway itself.
Technical details
CVE-2026-80054 is an Incorrect Permission Assignment for Critical Resource vulnerability (CWE-732) in Dell SCG versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). The vulnerability allows a low-privileged attacker with local access to the system to access or modify critical resources that should be restricted to privileged users. This represents a privilege escalation vector on the appliance or application host. The attack requires local access, meaning the attacker must have a valid local account or shell access to the system. Patches are available in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Updates available for version 5.36.00.16 (Appliance) and 5.36.00.00 (Application)