---
id: CVE-2026-79741
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in a Command ('Command Injection') vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in a Command ('Command Injection') vulnerability. An
  unauthentica…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-77
vendor: Dell
product: Secure Connect Gateway 5.0 - Application
affected:
  - secure_connect_gateway_5.0_-_application < 5.36.00.00 or later
  - secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T03:56:19.500413Z'
published: '2026-09-09'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T12:59:55.278Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-79741'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
tags:
  - cve.org
epss: 0.01533
epssPercentile: 0.73266
ingestedAt: '2026-09-11T16:45:47.911Z'
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

## Affected

- `secure_connect_gateway_5.0_-_application < 5.36.00.00 or later`
- `secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
