PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80238 Dell CVE debrief

Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 contain an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container to gain

Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

System administrators and security teams responsible for Dell SCG 5.0 Appliance and Application deployments should assess exposure, prioritize upgrades, and monitor for suspicious activity. Additionally, operators with SSH access to the SCG host and security teams managing vulnerability response should be aware of the potential risks and take necessary precautions to prevent exploitation.

Why it matters

CVE-2026-80238 is a critical vulnerability in Dell SCG 5.0 Appliance and Application that allows unauthenticated attackers to bypass protection mechanisms and gain root-level access to the host. System administrators and security teams should assess exposure, prioritize upgrades, and monitor for suspicious activity.

  • Potential for privilege escalation
  • Possible protection mechanism bypass
  • Risk of unauthorized access to sensitive data
  • Need for prompt upgrade and monitoring

Technical summary

The vulnerability is due to an exposed Docker socket, which allows an attacker to gain root-level access to the host without requiring a password. This exposed socket enables unauthorized privilege escalation, potentially leading to protection mechanism bypass and unauthorized access to sensitive data. Dell SCG 5.0 Appliance and Application versions are affected, with upgrades recommended to address this critical vulnerability. The vulnerability allows unauthenticated attackers to bypass protection mechanisms and gain root-level access to the host.

Defensive priority

Upgrade to the recommended versions at the earliest opportunity.

Recommended defensive actions

  • Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later
  • Upgrade Dell SCG 5.0 Application to version 5.36.00.00 or later
  • Restrict SSH access to the SCG host
  • Monitor for suspicious activity on the SCG host
  • Review compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Evidence is based on the CVE description and NVD assessment. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80238 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80238

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80238 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80238

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.