Junglewise Threat Intelligence

CVE-2026-80238: Dell Secure Connect Gateway execution with unnecessary privileges via Docker socket

CVE-2026-80238 · Severity: critical · CVSS 9.3 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a VPN/connectivity appliance used by enterprises to provide secure remote access. A vulnerability in versions prior to 5.36.00 allows attackers with local access to gain complete control of the system by exploiting an exposed Docker socket—either directly via SSH or by escaping from a container. This gives attackers root-level privileges without authentication, bypassing all security controls.

Technical details

The vulnerability is an execution with unnecessary privileges issue (CWE-250) affecting Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The root cause is an exposed Docker socket accessible to low-privileged users on the host and to container processes. Attack vectors include: (1) SSH access by a low-privileged operator who can leverage the Docker socket to gain root access without a password, or (2) a compromised service in the orchestrator container that can access the socket to escape the container and obtain host-level control. No authentication is required. The attack is local in scope but allows complete host compromise. Patches are available in the fixed versions.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Published in DSA-2026-382
  • 2026-09-07: patched: Fixed in Appliance 5.36.00.16 and Application 5.36.00.00

References

Related threats