CVE-2026-79640
published 2026-09-09CVE-2026-79640: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special…
PriorityP433medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.15%
4.6th percentile
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | secure_connect_gateway | < 5.36.00.00 | 5.36.00.00 |
| dell | secure_connect_gateway | < 5.36.00.16 | 5.36.00.16 |
| dell | secure_connect_gateway_5.0_appliance | < 5.36.00.16 or later | 5.36.00.16 or later |
| dell | secure_connect_gateway_5.0_application | < 5.36.00.00 or later | 5.36.00.00 or later |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Dell Secure Connect Gateway sql injection (WID-SEC-2026-3184)
vuldb·2026-09-10·CVSS 5.4
CVE-2026-79640 [MEDIUM] Dell Secure Connect Gateway sql injection (WID-SEC-2026-3184)
A vulnerability classified as critical was found in Dell Secure Connect Gateway. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2026-79640. The attack can be launched remotely. No exploit exists.
GHSA
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje
ghsa_unreviewed·2026-09-09
CVE-2026-79640 [MEDIUM] CWE-89 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-09
Published