Dell TechnologiesCVE-2026-79689
Dell Technologies Secure Connect Gateway 5.0: command injection
Medium5.3CVE-2026-79689 · Published Sep 9, 2026 · updated Sep 11, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Secure Connect Gateway 5.0 - Appliance Product | < 5.36.00.16 or later | 5.36.00.16 or later |
| Secure Connect Gateway 5.0 - Application Product | < 5.36.00.00 or later | 5.36.00.00 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 9 | Dell Technologies PowerScale OneFS: command injection | Medium6.7 | 9.13.1.1 or later+1 more |
| Sep 9 | Dell Technologies PowerScale OneFS: denial of service | Medium5.4 | 9.13.1.1 or later+1 more |
| Sep 9 | Dell Technologies PowerScale OneFS: improper authorization | Low3.5 | 9.7.1.16 or later+2 more |
| Sep 9 | Dell Technologies iDRAC10: command injection | High7.2 | iDRAC9 7.30.10.50 or later+2 more |
| Sep 9 | Dell Technologies Secure Connect Gateway 5.0: command injection | Medium5.3 | - Application 5.36.00.00 or later+1 more |
| Sep 9 | Dell Technologies Secure Connect Gateway 5.0: excessive privileges | Low3.4 | - Application 5.36.00.00 or later+1 more |