CVE-2026-80178
Local Privilege Escalation in Dell Secure Connect Gateway 5.0
CVE-2026-80178 is an improper privilege management flaw (CWE-269) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance and the Application editions. A low-privileged attacker who already has local access to the SCG host can exploit the flaw to elevate their privileges on the system, with the CVSS vector indicating high impact to confidentiality, integrity, and availability once escalated. Because exploitation requires local access, remote or internet-based attacks are not the primary risk; the concern is privilege escalation by users, services, or malware already inside the environment. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. There are currently no known public proofs of concept, no reports of exploitation in the wild, and the flaw is not listed in CISA's KEV catalog, with EPSS estimating only a ~0.1% chance of exploitation in the next 30 days.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later, and SCG 5.0 Application to version 5.36.00.00 or later. In the meantime, restrict interactive and SSH logins on SCG hosts to trusted administrators only, and audit local accounts and running services on those systems for signs of unexpected access.
| Dell Secure Connect Gateway 5.0 Appliance | All versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | All versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.