cbcvebase.
CVE-2026-80238
published 2026-09-07

CVE-2026-80238: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary…

PriorityP356critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
0.15%
4.4th percentile
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.

Affected

2 ranges
VendorProductVersion rangeFixed in
dellsecure_connect_gateway_5.0_appliance< 5.36.00.16 or later5.36.00.16 or later
dellsecure_connect_gateway_5.0_application< 5.36.00.00 or later5.36.00.00 or later
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.