VYPR
Vypr IntelligenceAI-generatedOct 9, 2026· 20 CVEs

Dell SCG Policy Manager: 19 Vulnerabilities Disclosed, Ranging from Auth Bypass to Code Execution

Dell Secure Connect Gateway (SCG) Policy Manager: 19 vulnerabilities disclosed, including High severity flaws affecting versions prior to 5.34.00.16.

Key findings

  • 19 vulnerabilities disclosed in Dell Secure Connect Gateway (SCG) Policy Manager on October 9, 2026.
  • All vulnerabilities affect versions prior to 5.34.00.16 and are fixed in version 5.34.00.16.
  • High severity flaws include SSRF, Missing Authentication, and Improper Certificate Validation.
  • Vulnerabilities range from authorization bypass and path traversal to information disclosure and code execution.
  • Attackers could gain elevated privileges, unauthorized access, and execute code.

On October 9, 2026, a batch of 19 vulnerabilities was disclosed for Dell Secure Connect Gateway (SCG) Policy Manager. These vulnerabilities, all affecting versions prior to 5.34.00.16, were disclosed within a one-hour window, indicating a coordinated disclosure event. The vulnerabilities present a range of risks, including elevation of privileges, unauthorized access, code execution, and information disclosure, with several rated as High severity.

Several vulnerabilities center on authorization and access control issues. CVE-2026-78341, a Medium severity bug, involves Incorrect Authorization, potentially leading to elevation of privileges and unauthorized access for a high-privileged remote attacker. Similarly, CVE-2026-78023 (High severity) and CVE-2026-78025 (High severity) involve Authorization Bypass Through User-Controlled Key and Missing Authentication for Critical Function, respectively, both exploitable by remote attackers with varying privilege levels. CVE-2026-76769, a Medium severity vulnerability, is due to a Missing Authorization flaw.

Other notable vulnerabilities include path traversal and SSRF flaws. CVE-2026-78340, a Medium severity Path Traversal vulnerability, could allow a local attacker to achieve code execution. Two Server-Side Request Forgery (SSRF) vulnerabilities, CVE-2026-78027 (Medium severity) and CVE-2026-78024 (High severity), could enable information disclosure and other impacts for high-privileged remote attackers.

A cluster of vulnerabilities relate to improper handling of resources and inputs. CVE-2026-78020, a High severity Improper Certificate Validation vulnerability, could lead to denial of service, information disclosure, and remote execution. CVE-2026-78019, another High severity flaw, involves Inclusion of Functionality from Untrusted Control Sphere, potentially leading to elevation of privileges and filesystem access. Additionally, CVE-2026-78339, a Medium severity Incorrect Permission Assignment for Critical Resource vulnerability, could result in information disclosure and protection mechanism bypass.

The batch also includes vulnerabilities such as Failing Open (CVE-2026-78022), Initialization of a Resource with an Insecure Default (CVE-2026-78018 and CVE-2026-78013), Improper Restriction of Excessive Authentication Attempts (CVE-2026-76779), and vulnerabilities related to input validation and error message generation (CVE-2026-78016, CVE-2026-78015, CVE-2026-78014, CVE-2026-78010, CVE-2026-78017).

All 19 disclosed vulnerabilities affect Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16. Dell has released version 5.34.00.16 to address these security weaknesses. Users are strongly advised to update to the patched version to mitigate the risks associated with these vulnerabilities.

This coordinated disclosure of numerous vulnerabilities highlights the importance of timely patching for SCG Policy Manager. The breadth of issues, ranging from authorization bypasses to code execution, underscores the need for diligent security management for this product. Users should prioritize updating their systems to version 5.34.00.16 to protect against potential exploitation.

AI-written article. Grounded in 20 CVE records listed below.