CVE-2026-79635
—Unauthenticated SSRF in Dell Secure Connect Gateway 5.0
CVE-2026-79635 is a Server-Side Request Forgery (SSRF) flaw (CWE-918) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance edition and the Application edition. An unauthenticated attacker with network access to the SCG can trigger the gateway to make forged requests, potentially leading to unauthorized access to internal resources reachable from the gateway. The CVSS 3.1 base score is 7.3 (High) with network attack vector, low attack complexity, and no privileges or user interaction required, with low impacts to confidentiality, integrity, and availability. Any organization running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 is affected. No public proof-of-concept, known exploited-vulnerability listing, or reported in-the-wild exploitation is currently known.
What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. In the meantime, restrict which clients can reach the SCG management interface and limit the gateway's outbound network access to required Dell endpoints. Inventory your environment for both appliance and application deployments, as both editions are separately affected.
| Dell Secure Connect Gateway 5.0 Appliance | All versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | All versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.