Junglewise Threat Intelligence

CVE-2026-80132: Dell Secure Connect Gateway missing authentication in critical function

CVE-2026-80132 · Severity: high · CVSS 8.1 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network security appliance and application that manages secure remote access and connectivity. Versions before 5.36.00.16 (appliance) and 5.36.00.00 (application) lack authentication on critical functions, allowing remote attackers to gain unauthorized access without credentials. This could lead to data theft, system compromise, or unauthorized network access by unauthenticated users.

Technical details

The vulnerability is a missing authentication control on critical functions in Dell SCG 5.0, classified as CWE-306. An unauthenticated attacker with network access can exploit this by sending requests to unprotected endpoints, bypassing authentication mechanisms entirely. No user interaction or special conditions are required; the attack is straightforward remote exploitation. An attacker can gain unauthorized access to the system, potentially leading to full compromise. The fix requires upgrading to SCG 5.0 Appliance version 5.36.00.16 or later, or SCG 5.0 Application version 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: CVE-2026-80132 published
  • 2026-09-07: patched: Patches available: SCG 5.0 Appliance 5.36.00.16+, SCG 5.0 Application 5.36.00.00+

References

Related threats