CVE-2026-78490
largeUnauthenticated client-side request forgery in Dell Secure Connect Gateway 5.0
CVE-2026-78490 is an improper restriction of excessive authentication attempts (CWE-307) in Dell Secure Connect Gateway (SCG) 5.0, meaning the software fails to limit or lock out repeated authentication attempts. An unauthenticated attacker with remote network access can trigger the flaw by sending excessive or crafted authentication requests to the gateway. Dell states that successful exploitation could lead to client-side request forgery, and the CVSS 3.1 vector rates the impact as high on confidentiality with no integrity or availability impact. Organizations running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later, verifying deployed versions in the gateway's administration interface. Until patched, restrict access to the gateway's authentication interface to trusted management networks or VPN rather than exposing it directly to the internet, since the flaw is exploitable by unauthenticated remote attackers. Continue monitoring Dell security advisories, as no public PoC or in-the-wild exploitation is currently known.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-307
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.