Junglewise Threat Intelligence

CVE-2026-80178: Dell Secure Connect Gateway privilege management vulnerability

CVE-2026-80178 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a virtual appliance and application used for secure network access and connectivity. A low-privileged local attacker can escalate their privileges to gain full system access on affected versions, potentially compromising the entire gateway and all traffic flowing through it.

Technical details

CVE-2026-80178 is an improper privilege management vulnerability in Dell SCG versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). The vulnerability requires local access and low-level privileges to exploit, allowing an attacker to escalate to higher privileges. The root cause involves insufficient separation or validation of privilege levels during operations. Exploitation grants the attacker elevated system permissions, potentially leading to full control of the gateway appliance. Patches are available in the versions specified above.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Published on NVD and Dell advisory DSA-2026-382
  • 2026-09-07: patched: Patches available: SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00

References

Related threats