CVE-2026-80130
largeRelative Path Traversal RCE in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains a relative path traversal flaw (CWE-23) that allows a low-privileged remote user to reference files outside the intended directory. By sending a crafted path that the gateway fails to normalize, the attacker can escape the application's working directory and achieve remote code execution on the SCG host. Successful exploitation carries high impact on confidentiality, integrity, and availability (CVSS 3.1 8.8) on a system that typically sits inside the customer network brokering support connectivity for Dell infrastructure. Users running SCG 5.0 Appliance before 5.36.00.16 or SCG 5.0 Application before 5.36.00.00 are affected. No public proof-of-concept, CISA KEV listing, or confirmed exploitation is known, and EPSS currently estimates only about a 0.3% chance of exploitation within 30 days.
What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later per Dell's security advisory. Until patched, restrict gateway user and administrative access to trusted networks and review which low-privileged accounts can reach the SCG instance. Monitor Dell's advisory and threat reporting for updates, since no public PoC or in-the-wild exploitation is currently documented.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-23
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.