Junglewise Threat Intelligence

CVE-2026-80134: Dell Secure Connect Gateway hard-coded credentials

CVE-2026-80134 · Severity: high · CVSS 7.7 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a secure network connectivity appliance used to manage remote access and VPN connections. This vulnerability allows an unauthenticated attacker with network access to gain unauthorized access to the system using hard-coded credentials, potentially enabling full system compromise without needing legitimate user accounts.

Technical details

The vulnerability is a hard-coded credentials flaw in Dell SCG 5.0 Appliance (versions before 5.36.00.16) and Dell SCG 5.0 Application (versions before 5.36.00.00). An unauthenticated attacker with remote network access can exploit this by leveraging exposed default credentials built into the application code or configuration, leading to unauthorized access to critical functions. The attack requires no authentication or user interaction and can be performed directly over the network. Patches are available in the specified fixed versions.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 versions prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 versions prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed

References

Related threats