Junglewise Threat Intelligence

CVE-2026-80124: Dell Secure Connect Gateway sensitive information insertion into log file

CVE-2026-80124 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a network security appliance and application used to manage secure remote access and connectivity. A vulnerability allows a low-privileged attacker with local system access to insert sensitive information into application log files, potentially exposing confidential data such as credentials, tokens, or business information to unauthorized users who can read logs.

Technical details

CVE-2026-80124 is an Insertion of Sensitive Information into Log File vulnerability affecting Dell Secure Connect Gateway (SCG) versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). A low-privileged local attacker can exploit this flaw to write sensitive data directly into application log files, circumventing intended data protection mechanisms. The attack requires local system access but no elevated privileges. Successful exploitation results in information disclosure, as sensitive information becomes accessible to any user or process with log file read permissions. Patches are available in SCG 5.36.00.16 and later for the Appliance and 5.36.00.00 and later for the Application.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-80124 published on NVD
  • 2026-09-09: advisory: Dell DSA-2026-382 security update advisory released

References

Related threats