Execution with Unnecessary Privileges in Dell SCG 5.0 Appliance
CVE-2026-80238

9.3CRITICAL

What is CVE-2026-80238?

The Dell SCG 5.0 Appliance and its associated applications prior to specified versions exhibit a vulnerability that allows an unauthenticated attacker with local access to exploit execution with unnecessary privileges. This can lead to a bypass of protection mechanisms, enabling low-privileged operators with SSH access to gain root-level control of the host system without a password. Furthermore, an attacker exploiting a service within the orchestrator container can escape the container boundary via the exposed Docker socket, gaining unauthorized access to host-level resources. Customers are strongly advised to upgrade their systems to remediate this issue and enhance their security posture.

Affected Version(s)

Secure Connect Gateway 5.0 - Appliance 0 < 5.36.00.16 or later

Secure Connect Gateway 5.0 - Application 0 < 5.36.00.00 or later

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.