---
id: CVE-2026-78488
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an OS Command ('OS Command Injection')
  vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an OS Command ('OS Command Injection')
  vulnerability. A low pr…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-78
vendor: dell
product: secure_connect_gateway
affected:
  - secure_connect_gateway < 5.36.00.00
  - secure_connect_gateway < 5.36.00.16
patched:
  - secure_connect_gateway 5.36.00.16
published: '2026-09-07'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:22:54.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78488'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
epss: 0.03249
epssPercentile: 0.8779
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T14:42:14.602938Z'
ingestedAt: '2026-09-08T15:33:26.978Z'
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.

## Affected

- `secure_connect_gateway < 5.36.00.00`
- `secure_connect_gateway < 5.36.00.16`

## Remediation

Upgrade past the affected range:

- `secure_connect_gateway 5.36.00.16`
