CVE-2026-61410
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity.
In plain language
AI Act nowDell Secure Connect Gateway 5.0 versions before 5.36.00.16 on Appliance or 5.36.00.00 on Application let an outsider take over the system, so affected small businesses should act now.
Unauthenticated network-based remote command execution caused by missing authorization in Dell Secure Connect Gateway 5.0 permits arbitrary command execution via a specially crafted request.
What to do now
- Check whether you run Dell Secure Connect Gateway 5.0 and identify whether it is the Appliance or Application edition.
- Upgrade Appliance systems to 5.36.00.16 or later.
- Upgrade Application systems to 5.36.00.00 or later.
- Until upgraded, restrict network access to the gateway to only required Dell and administrator connections.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61410 and every CVE in our database. Create a free account — no credit card required.
Create Free Account