CVE-2026-78490
published 2026-09-09CVE-2026-78490: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.29%
21.5th percentile
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | secure_connect_gateway | < 5.36.00.00 | 5.36.00.00 |
| dell | secure_connect_gateway | < 5.36.00.16 | 5.36.00.16 |
| dell | secure_connect_gateway_5.0_appliance | < 5.36.00.16 or later | 5.36.00.16 or later |
| dell | secure_connect_gateway_5.0_application | < 5.36.00.00 or later | 5.36.00.00 or later |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Dell Secure Connect Gateway prior 5.36.00.16/5.36.00.00 excessive authentication (EUVD-2026-74850 / WID-SEC-2026-3184)
vuldb·2026-09-10·CVSS 7.5
CVE-2026-78490 [HIGH] Dell Secure Connect Gateway prior 5.36.00.16/5.36.00.00 excessive authentication (EUVD-2026-74850 / WID-SEC-2026-3184)
A vulnerability marked as problematic has been reported in Dell Secure Connect Gateway. This impacts an unknown function. Performing a manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is known as CVE-2026-78490. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability.
ghsa_unreviewed·2026-09-09
CVE-2026-78490 [HIGH] CWE-307 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-09
Published