CVE-2026-80127
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.88%
- CWE
- CWE-78
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- Dell Secure Connect Gateway 5.0 - Application
- Dell Secure Connect Gateway 5.0 - Appliance
Weakness type
Related vulnerabilities
- CVE-2026-17176 — OS command injection Vulnerability in Deco BE11000
- CVE-2026-78569 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-78575 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-79724 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81550 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82095 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82098 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82099 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software