← Back to overview

A critical Missing Authorization vulnerability (CVE-2026-61410) has been identified in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted request to the application, bypassing code execution restrictions and achieving remote command execution. The vulnerability is rated critical due to its unauthenticated and remote exploitability. No credentials are required to exploit this flaw, significantly lowering the barrier for attackers. Dell has issued a security advisory (DSA-2026-382) and strongly recommends customers upgrade to the patched versions at the earliest opportunity.

Affected products

  • Dell SCG 5.0 Appliance
  • Dell SCG 5.0 Application
  • Dell Secure Connect Gateway

Related CVE's

  • CVE-2026-61410

Categories

  • Enterprise Applications
  • Identity & Access
  • Zero-Day Vulnerabilities