CVE-2026-80166
largeLocal Privilege Escalation (Improper Privilege Management) in Dell Secure Connect Gateway 5.0
CVE-2026-80166 is an improper privilege management flaw (CWE-269) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance editions before 5.36.00.16 and the Application editions before 5.36.00.00. An unauthenticated attacker who already has local access to the appliance or to the host running the SCG Application can exploit the flaw to elevate privileges on the system. Because the CVSS impact ratings are high for confidentiality, integrity and availability, successful privilege escalation could give the attacker broad control over the gateway, which many enterprises use as the relay for Dell support telemetry and remote support connectivity. Any organization running an affected SCG 5.0 Appliance or Application is in scope, though exploitation requires local access rather than network reachability. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.1%, so no active exploitation is known.
What to do: Upgrade SCG 5.0 Appliances to version 5.36.00.16 or later and SCG 5.0 Applications to version 5.36.00.00 or later. Because exploitation requires local access, also review who has console, SSH or local logon access to SCG appliances and to the servers hosting the SCG Application, and restrict it to administrative staff. Check Dell's security advisory for this CVE for any additional guidance.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.