Junglewise Threat Intelligence

CVE-2026-80166: Dell Secure Connect Gateway privilege escalation via improper privilege management

CVE-2026-80166 · Severity: high · CVSS 7.8 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a secure remote access appliance used to manage and control corporate network connections. A vulnerability in SCG allows a low-privileged local user to elevate their privileges to higher levels without proper authorization, potentially gaining administrative control of the system and access to sensitive corporate data.

Technical details

This is an Improper Privilege Management vulnerability (CWE-269) in Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively. The vulnerability allows an authenticated local attacker with low privileges to escalate to higher privilege levels due to inadequate privilege validation. The attack vector is local and requires prior authentication (PR:L), but no user interaction. An attacker can achieve elevation of privileges to gain unauthorized access to system resources and functionality. Patches are available in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application).

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Published as CVE-2026-80166
  • 2026-09-07: patched: Patch available: SCG 5.0 Appliance 5.36.00.16, SCG 5.0 Application 5.36.00.00

References

Related threats