CVE-2026-79692
—Unauthenticated Filesystem Access via File Path Control in Dell Secure Connect Gateway 5.0
CVE-2026-79692 is an External Control of File Name or Path vulnerability (CWE-73) in Dell Secure Connect Gateway (SCG) 5.0, affecting Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. Because the affected component accepts an attacker-controlled file name or path, an unauthenticated remote attacker can direct file operations to unintended locations on the target filesystem. Successful exploitation may allow the attacker to access, and potentially read or influence, files on the SCG Appliance or Application host. Any organization running Dell SCG 5.0 in the affected version ranges is exposed, with the Appliance and Application (software) deployment variants both impacted. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later, and SCG 5.0 Application to version 5.36.00.00 or later. In the interim, restrict network access to the SCG management interface to trusted administrative networks and verify the deployed variant (Appliance vs. Application) and running version. Monitor Dell's security advisory for updates, as no public PoC exists yet but exploitation may follow disclosure.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.