Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-80169

CVE-2026-80169: Dell Secure Connect Gateway Log Vulnerability

CVE-2026-80169 is an information disclosure flaw in Dell Secure Connect Gateway where sensitive data is inserted into log files. Low privileged attackers with local access can exploit this to expose confidential information. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-80169 Overview

CVE-2026-80169 affects Dell Secure Connect Gateway (SCG) 5.0, both the Appliance and Application editions. The flaw is an Insertion of Sensitive Information into Log File weakness classified under [CWE-532]. Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 write sensitive data to log files accessible to low-privileged local users. An authenticated local attacker can read these logs to obtain information that should remain confidential. Dell published fixes under advisory DSA-2026-382.

Critical Impact

A low-privileged local user on a Dell SCG 5.0 host can read log files containing sensitive information, resulting in information exposure with no user interaction required.

Affected Products

  • Dell Secure Connect Gateway 5.0 Appliance (Virtual Edition) prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
  • Deployments referenced by CPE cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:* and cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*

Discovery Timeline

  • 2026-09-09 - CVE CVE-2026-80169 published to NVD
  • 2026-09-09 - Last updated in NVD database
  • 2026-09-09 - Dell publishes security advisory DSA-2026-382

Technical Details for CVE-2026-80169

Vulnerability Analysis

Dell Secure Connect Gateway is the remote support and telemetry channel used to connect Dell infrastructure to Dell backend services. In the affected releases, one or more SCG components write sensitive information into log files that are readable by accounts with only local, low-privilege access on the appliance or application host. The behavior maps to [CWE-532]: Insertion of Sensitive Information into Log File.

The issue does not enable code execution, tampering, or denial of service. It compromises confidentiality only. Exploitation requires the attacker to already hold a valid local account on the SCG host, so the vulnerability is most relevant in multi-tenant administrative environments or as a post-compromise privilege-context expansion primitive.

Root Cause

The root cause is application logging that fails to redact or suppress sensitive fields before writing them to disk. Log destinations retain file permissions that permit read access by non-administrative local users, which turns routine diagnostic logging into a disclosure channel. Dell has not published the specific fields or log paths involved; refer to DSA-2026-382 for vendor-provided detail.

Attack Vector

The attack vector is local and authenticated. An attacker with a low-privileged shell or interactive session on the Dell SCG host reads accessible log files and extracts the sensitive content. No network exposure, user interaction, or elevated privileges are required beyond a valid local account. No public proof-of-concept, exploit code, or in-the-wild exploitation has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.

See the Dell advisory for technical details specific to the impacted log paths and data fields.

Detection Methods for CVE-2026-80169

Indicators of Compromise

  • Access to SCG log directories by user accounts that are not part of the administrative or service groups expected to read them.
  • Copy, scp, or archive operations targeting SCG log files performed by non-administrative local users.
  • Unexpected outbound transfer of SCG log artifacts from the appliance or application host.

Detection Strategies

  • Audit filesystem access on the SCG host for read events against log directories, correlating the acting user identity against an allow list of expected service accounts.
  • Inventory installed Dell SCG versions and flag any Appliance build below 5.36.00.16 or Application build below 5.36.00.00.
  • Review historical log file permissions and ownership to identify whether sensitive artifacts were previously world-readable or group-readable.

Monitoring Recommendations

  • Forward SCG operating system audit logs and application logs to a centralized SIEM for retention and correlation.
  • Alert on shell activity by non-administrative accounts on SCG hosts, including file read patterns against /var/log and Dell application log directories.
  • Track authentication events on the SCG appliance to detect anomalous local logons that precede log file access.

How to Mitigate CVE-2026-80169

Immediate Actions Required

  • Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later, and Dell SCG 5.0 Application to version 5.36.00.00 or later, as directed by DSA-2026-382.
  • Review and reduce the set of local accounts that hold shell or interactive access on SCG hosts.
  • Rotate any credentials, tokens, or secrets that may have been recorded in SCG logs prior to patching.

Patch Information

Dell has released fixed builds addressing CVE-2026-80169. Apply Dell SCG 5.0 Appliance 5.36.00.16 or later, or Dell SCG 5.0 Application 5.36.00.00 or later. Full remediation details are documented in the vendor advisory DSA-2026-382.

Workarounds

  • Restrict read permissions on SCG log directories to the SCG service account and administrators only, where operationally feasible.
  • Remove non-essential local user accounts from SCG hosts and enforce role-based access for operators.
  • Purge or archive historical log files that predate the patch to a controlled location with restricted access.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.