CVE-2026-79972
—SQL Injection in Dell Secure Connect Gateway 5.0 Appliance and Application
CVE-2026-79972 is an SQL injection flaw (CWE-89) in Dell Secure Connect Gateway (SCG) 5.0, affecting the Appliance distribution in versions prior to 5.36.00.16 and the Application distribution in versions prior to 5.36.00.00. A remote attacker who already holds high privileges on the gateway can supply crafted input that is not properly neutralized before being used in SQL commands. Successful exploitation could lead to unauthorized access, with the CVSS vector indicating high impact to confidentiality, integrity, and availability. Any organization running Dell SCG 5.0 — the on-premises support connectivity tool used to link Dell infrastructure to Dell support services — is affected while running an affected version. There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. Inventory deployed gateways (check the current version in the SCG admin console or CLI) and prioritize internet-reachable or multi-site appliance deployments. Until patched, restrict access to the gateway's management interfaces and limit the number of high-privilege accounts, since exploitation requires high privileges.
| dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.