---
id: CVE-2026-61409
title: >-
  Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to
  5.36.00.00, contains an Improper Neutralization of Special Elements used in an
  OS Command ('OS Command Injection') vulnerability
summary: >-
  Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to
  5.36.00.00, contains an Improper Neutralization of Special Elements used in an
  OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker
  with remot…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-78
vendor: dell
product: secure_connect_gateway
affected:
  - secure_connect_gateway < 5.36.00.00
patched:
  - secure_connect_gateway 5.36.00.00
published: '2026-09-07'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T01:15:33.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61409'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
epss: 0.01354
epssPercentile: 0.70393
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T12:56:19.486886Z'
ingestedAt: '2026-09-08T15:33:26.977Z'
---

## Overview

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

## Affected

- `secure_connect_gateway < 5.36.00.00`

## Remediation

Upgrade past the affected range:

- `secure_connect_gateway 5.36.00.00`
