← Terug naar overzicht

A critical privilege escalation vulnerability (CVE-2026-80238) has been identified in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The flaw is classified as Execution with Unnecessary Privileges and allows a low-privileged user with SSH access to gain root-level control of the host by exploiting an exposed Docker socket, without requiring a password. Additionally, an attacker who compromises a containerized service can use the same Docker socket to escape the container and achieve full host-level control. The vulnerability can also be leveraged by unauthenticated attackers with local access, leading to protection mechanism bypass. Dell has rated this vulnerability as critical and strongly recommends customers upgrade immediately to the patched versions.

Affected products

  • Dell SCG 5.0 Appliance
  • Dell SCG 5.0 Application
  • Dell Secure Connect Gateway

Related CVE's

  • CVE-2026-80238

Categories

  • Cloud & Virtualization
  • Enterprise Applications
  • Identity & Access