CVE-2026-80131
largeUnauthenticated Path Traversal RCE in Dell Secure Connect Gateway 5.0
CVE-2026-80131 is an improper limitation of a pathname to a restricted directory (path traversal, CWE-22) in Dell Secure Connect Gateway 5.0, affecting the SCG 5.0 Appliance before 5.36.00.16 and the SCG 5.0 Application before 5.36.00.00. An unauthenticated attacker with network access to the gateway can submit crafted path references that escape the intended restricted directory, and Dell notes this can lead to remote execution of attacker code. Successful exploitation would therefore yield code execution on the SCG host, which typically sits inside enterprise networks brokering connectivity between Dell hardware and Dell support services. Only deployments of the two named SCG 5.0 products running versions earlier than the fixed releases are affected. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days.
What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later. In the interim, restrict network access to the gateway's service interfaces to trusted management networks, since the flaw requires no authentication. Administrators should inventory whether they run the Appliance or Application variant and verify the installed version through the SCG administration interface before patching.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.