Dell TechnologiesCVE-2026-61409
Dell Technologies Secure Connect Gateway: command injection
High7.3CVE-2026-61409 · Published Sep 7, 2026 · updated Sep 16, 2026
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Secure Connect Gateway (SCG) 5.0 Application Product | < 5.36.00.00 or later | 5.36.00.00 or later |
| Secure Connect Gateway 5.0 - Appliance Product | < 5.36.00.16 or later | 5.36.00.16 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | Medium5.5 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: cleartext secrets | Medium5.5 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | Medium5.9 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | Medium6.5 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: improper privilege management | High7.8 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | Medium5.5 | - Application 5.36.00.00 or later+1 more |