Junglewise Threat Intelligence

CVE-2026-80056: Dell Secure Connect Gateway sensitive information in log file

CVE-2026-80056 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a virtual appliance used to provide secure remote access to corporate networks. This vulnerability allows a low-privileged local attacker to read sensitive information that has been written to application log files, potentially exposing credentials, authentication tokens, or other confidential data stored in system logs.

Technical details

This vulnerability is an Insertion of Sensitive Information into Log File (CWE-532) affecting Dell SCG 5.0 Application and Appliance. A low-privileged attacker with local access to the system can exploit this by reading log files that inadvertently contain sensitive information such as credentials or tokens. The attack requires local access but no authentication. The impact is information disclosure; an attacker can potentially obtain credentials or tokens to escalate privileges or gain unauthorized access to the system or connected resources. Patches are available: update SCG 5.0 Appliance to version 5.36.00.16 or later, and SCG 5.0 Application to version 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Publicly disclosed via NVD and Dell security advisory DSA-2026-382
  • 2026-09-07: patched: Patches available: SCG 5.0 Appliance 5.36.00.16+ and SCG 5.0 Application 5.36.00.00+

References

Related threats