CVE-2026-79946
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-87
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Dell Secure Connect Gateway 5.0 - Application
- Dell Secure Connect Gateway 5.0 - Appliance
Weakness type
Related vulnerabilities
- CVE-2026-54002 — Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
- CVE-2026-55661 — TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
- CVE-2026-55237 — AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
- CVE-2026-46492 — md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
- CVE-2026-25688 — Apache Answer: XSS in AI Answer Rendering
- CVE-2026-45314 — Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
- CVE-2026-42458 — Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
- CVE-2026-42235 — n8n: XSS via MCP OAuth client