---
id: CVE-2026-79689
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an OS Command ('OS Command Injection')
  vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an OS Command ('OS Command Injection')
  vulnerability. An unaut…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-78
vendor: Dell
product: Secure Connect Gateway 5.0 - Application
affected:
  - secure_connect_gateway_5.0_-_application < 5.36.00.00 or later
  - secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T03:56:21.570749Z'
published: '2026-09-09'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T13:06:07.370Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-79689'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
tags:
  - cve.org
epss: 0.0191
epssPercentile: 0.78913
ingestedAt: '2026-09-11T16:45:47.911Z'
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

## Affected

- `secure_connect_gateway_5.0_-_application < 5.36.00.00 or later`
- `secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
