Multiple security vulnerabilities affecting Dell Secure Connect Gateway versions The flaws affect Dell SCG 5 have been identified in Dell Secure Connect Gateway 5.0 Appliance and Application builds before 5.36.00.16. These flaws present a significant risk as they allow unauthorized access, remote code execution, and root-level takeover. Dell reports no active exploitation at this time.
CVE-2026-80172 (CVSS 9.8 — Severity): This vulnerability allows an unauthenticated attacker to forge admin tokens and gain unauthorized access due to the lack of nonce validation or time limit on requests. An attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens indefinitely.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Dell Secure Connect Gateway versions The flaws affect Dell SCG 5 have been identified in Dell Secure Connect Gateway 5.0 Appliance and Application builds before 5.36.00.16. These flaws present a significant risk as they allow unauthorized access, remote code execution, and root-level takeover. Dell reports no active exploitation at this time.
CVE-2026-80172 (CVSS 9.8 — Severity): This vulnerability allows an unauthenticated attacker to forge admin tokens and gain unauthorized access due to the lack of nonce validation or time limit on requests. An attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens indefinitely.[emaillocker id="1283"]
CVE-2026-61410 (CVSS 9.4 — Severity): A missing-authorization flaw allows remote command execution through a crafted request that bypasses code-execution restrictions.
CVE-2026-80238: This vulnerability lets a low-privileged operator abuse an exposed Docker socket to reach root and escape the container.
We recommend you to update Dell Secure Connect Gateway to version 5.36.00.00 or later.
The following reports contain further technical details:
[/emaillocker]