Dell Technologies Secure Connect Gateway 5.0: excessive privileges
Critical9.3CVE-2026-80238 · Published Sep 7, 2026 · updated Sep 11, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Secure Connect Gateway 5.0 - Appliance Product | < 5.36.00.16 or later | 5.36.00.16 or later |
| Secure Connect Gateway 5.0 - Application Product | < 5.36.00.00 or later | 5.36.00.00 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-250
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | Medium5.5 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: cleartext secrets | Medium5.5 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | Medium5.9 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | Medium6.5 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: improper privilege management | High7.8 | - Application 5.36.00.00 or later+1 more |
| Sep 7 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | Medium5.5 | - Application 5.36.00.00 or later+1 more |