CVE-2026-78485
largeUnauthenticated Path Traversal in Dell Secure Connect Gateway 5.0
CVE-2026-78485 is a path traversal flaw (CWE-22) in Dell Secure Connect Gateway 5.0, where user-controlled path input is not properly restricted to an allowed directory. A remote attacker with no credentials or user interaction can send crafted path-based requests to the gateway, causing file or resource access outside the intended restricted directory. Successful exploitation may lead to unauthorized access to sensitive data or gateway functionality (CVSS v3.1 7.3 high, with modest confidentiality, integrity, and availability impact per the vector). Affected deployments are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later. Until patched, restrict network access to the gateway's management interface (firewall/ACLs, VPN-only access) and review gateway access logs for unexpected remote requests. Since no public PoC exists, prioritize internet-facing or otherwise remotely reachable SCG deployments for remediation.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.