---
id: CVE-2026-79946
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Alternate XSS Syntax vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote
  access coul…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-87
vendor: dell
product: secure_connect_gateway
affected:
  - secure_connect_gateway < 5.36.00.00
  - secure_connect_gateway < 5.36.00.16
patched:
  - secure_connect_gateway 5.36.00.16
published: '2026-09-09'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:17:11.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79946'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T13:36:26.428044Z'
epss: 0.00353
epssPercentile: 0.26339
ingestedAt: '2026-09-14T15:23:07.419Z'
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

## Affected

- `secure_connect_gateway < 5.36.00.00`
- `secure_connect_gateway < 5.36.00.16`

## Remediation

Upgrade past the affected range:

- `secure_connect_gateway 5.36.00.16`
