Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used to provide secure connections to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain an improper locking vulnerability that allows a low-privileged attacker with remote network access to bypass filesystem access controls, potentially exposing sensitive system files and data.
Technical details
The vulnerability is classified as an Improper Locking issue (CWE-667 equivalent), where insufficient synchronization or locking mechanisms in the SCG codebase allow concurrent access to protected resources. A low-privileged attacker with remote network access can exploit this vulnerability to gain unauthorized filesystem access. The attack requires no user interaction and can be executed over the network. Dell has released patches in versions 5.36.00.16 (appliance) and 5.36.00.00 (application) to address the locking mechanism deficiency.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: CVE-2026-80126 published and Dell security advisory DSA-2026-382 released