Dell Secure Connect Gateway 5.0 contains a command injection flaw (CWE-77) that an unauthenticated remote attacker could exploit to achieve script injection, with NVD scoring it 9.8 CRITICAL against Dell's own 5.3 MEDIUM rating.
What Is It
CVE-2026-79941 is an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability affecting Dell SCG 5.0. Per Dell's description, "an unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection."
The CVE was published 2026-09-09 and reached "Analyzed" status the same day. It carries two conflicting CVSS 3.1 assessments:
- Dell (secondary): 5.3 MEDIUM,
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N(low confidentiality impact only) - NVD (primary): 9.8 CRITICAL,
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H(high impact across confidentiality, integrity, and availability)
Both agree on the exploitability half of the vector: network-reachable, low attack complexity, no privileges, no user interaction. Exploitability subscore is 3.9; the maximum.
Why It Matters
Secure Connect Gateway is Dell's remote support and telemetry conduit into customer infrastructure, so an internet- or management-network-reachable instance is an attractive pivot. The pre-authentication requirement is nil and complexity is low, which is consistent with the SSVC decision points recorded by CISA-ADP in the NVD record for this CVE: automatable: yes with technicalImpact: partial.
That same CISA-ADP SSVC block currently records exploitation: none. CVE-2026-79941 is also not listed in the CISA Known Exploited Vulnerabilities catalog as of publication. Neither signal is a guarantee: absence from KEV means CISA has not added the CVE, not that exploitation has been ruled out, and defenders should treat the low barrier to exploitation, not the current KEV status, as the driver for patch urgency.
What's Vulnerable
- Dell Secure Connect Gateway 5.0 – Appliance (virtual edition): all versions prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 – Application: all versions prior to 5.36.00.00
Versions at or above those builds are listed as unaffected.
Patch Status
Dell has shipped fixes. Upgrade the Appliance to 5.36.00.16 or later and the Application to 5.36.00.00 or later, per Dell advisory DSA-2026-382. Because the CVE is not in the KEV catalog, no BOD 22-01 remediation deadline applies to federal civilian agencies, but that carries no implication about the underlying risk. Note that DSA-2026-382 covers multiple vulnerabilities, so the same update addresses additional issues beyond this one.
Sources
- NVD, CVE-2026-79941 (includes the CISA-ADP SSVC decision points cited above): https://nvd.nist.gov/vuln/detail/CVE-2026-79941
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Dell Security Advisory DSA-2026-382; Security Update for Dell Secure Connect Gateway Virtual Edition, Multiple Vulnerabilities: https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities