CVE-2026-61410

9.4

Dell · Secure Connect Gateway 5.0

A missing authorization vulnerability in Dell Secure Connect Gateway 5.0 allows unauthenticated remote attackers to execute arbitrary commands on the target system.

Executive summary

A critical missing authorization vulnerability in Dell Secure Connect Gateway 5.0 allows unauthenticated remote attackers to achieve remote code execution on affected appliances and applications.

Vulnerability

The flaw is a missing authorization vulnerability (CWE-862) that allows an unauthenticated, remote attacker to bypass security controls and execute commands by sending a specially crafted request to the application.

Business impact

This vulnerability carries a CVSS score of 9.4, indicating an extreme risk to the confidentiality, integrity, and availability of the affected system. Successful exploitation grants an attacker full remote command execution capabilities, which could lead to complete system compromise, unauthorized data exfiltration, and lateral movement within the enterprise network.

Remediation

Immediate Action: Upgrade the Dell Secure Connect Gateway 5.0 Application to version 5.36.00.00 or later, and the Appliance to version 5.36.00.16 or later, as specified in the official Dell security advisory DSA-2026-382.

Proactive Monitoring: Inspect system and application access logs for anomalous, unauthorized requests or unexpected shell execution patterns originating from unknown IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict request filtering rules to identify and block potentially malicious, specially crafted requests targeting the gateway interface until the patch can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full system compromise by unauthenticated actors, organizations must prioritize the immediate application of the vendor-provided updates. Failure to patch these gateway instances creates a significant, direct entry point for threat actors into the environment.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources