Junglewise Threat Intelligence

CVE-2026-80123: Dell Secure Connect Gateway SSRF in remote access

CVE-2026-80123 · Severity: high · CVSS 7.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used to enable secure connections to corporate networks. Versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain a Server-Side Request Forgery vulnerability that allows unauthenticated remote attackers to make unauthorized requests to internal systems, potentially causing service disruption or exposing internal infrastructure.

Technical details

CVE-2026-80123 is a Server-Side Request Forgery (SSRF) vulnerability in Dell SCG 5.0. The vulnerability allows an unauthenticated attacker with remote network access to exploit the flaw without authentication requirements or user interaction. An attacker can craft malicious requests that cause the SCG appliance or application to make requests to internal systems or external targets on behalf of the attacker, potentially leading to denial of service, information disclosure, or further lateral movement within the network. The vulnerability is patched in SCG 5.0 Appliance version 5.36.00.16 and later, and SCG 5.0 Application version 5.36.00.00 and later.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-80123 published

References

Related threats