CVE-2026-79638
published 2026-09-09CVE-2026-79638: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.20%
10.3th percentile
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | secure_connect_gateway | < 5.36.00.00 | 5.36.00.00 |
| dell | secure_connect_gateway | < 5.36.00.16 | 5.36.00.16 |
| dell | secure_connect_gateway_5.0_appliance | < 5.36.00.16 or later | 5.36.00.16 or later |
| dell | secure_connect_gateway_5.0_application | < 5.36.00.00 or later | 5.36.00.00 or later |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Dell Secure Connect Gateway up to 5.36.00.00 cross site scripting (WID-SEC-2026-3184)
vuldb·2026-09-10·CVSS 5.3
CVE-2026-79638 [MEDIUM] Dell Secure Connect Gateway up to 5.36.00.00 cross site scripting (WID-SEC-2026-3184)
A vulnerability was found in Dell Secure Connect Gateway. It has been declared as problematic. The impacted element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-79638. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability.
ghsa_unreviewed·2026-09-09
CVE-2026-79638 [MEDIUM] CWE-693 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-09
Published