Junglewise Threat Intelligence

CVE-2026-80129: Dell Secure Connect Gateway path traversal in application

CVE-2026-80129 · Severity: medium · CVSS 6.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a secure remote access solution that allows organizations to safely connect users to corporate resources. Versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain a path traversal vulnerability that allows an unauthenticated attacker with network access to read arbitrary files from the system, potentially leading to remote code execution and complete system compromise.

Technical details

The vulnerability is a path traversal (CWE-22) flaw in Dell SCG 5.0 that permits an unauthenticated, network-accessible attacker to traverse directory restrictions and access files outside intended boundaries. No authentication is required to exploit this issue. The attack is remotely executable via specially crafted requests to the application. Successful exploitation can lead to remote code execution and system takeover. Patches are available in Appliance version 5.36.00.16 and Application version 5.36.00.00.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Patches available in SCG Appliance 5.36.00.16 and Application 5.36.00.00

References

Related threats