Junglewise Threat Intelligence

CVE-2026-80130: Dell Secure Connect Gateway relative path traversal to RCE

CVE-2026-80130 · Severity: high · CVSS 7.1 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used to manage and protect network connectivity. A relative path traversal vulnerability in SCG 5.0 allows a low-privileged remote attacker to read, write, or manipulate files outside their intended directory, potentially leading to remote code execution and complete system compromise.

Technical details

The vulnerability is a relative path traversal (CWE-23) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. A low-privileged attacker with network access can exploit this flaw by crafting requests containing directory traversal sequences (e.g., "../") to access files outside the intended application directory. The vulnerability can lead to remote code execution. The attack does not require authentication, though the attacker must have some initial access or ability to reach the vulnerable endpoint. Dell has released patches in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application).

Affected products

  • Dell Secure Connect Gateway 5.0 prior to 5.36.00.16 (Appliance) and prior to 5.36.00.00 (Application)

Timeline

  • 2026-09-07: disclosed: CVE-2026-80130 published on NVD

References

Related threats