CVE-2026-80172
Dell SCG 5.0 Appliance and Application versions before 5.36.00.16 and 5.36.00.00, respectively, have a critical flaw that lets an unauthenticated attacker gain administrative access by replaying captured requests.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Dell SCG 5.0 Appliance (pre‑5.36.00.16) and Dell SCG 5.0 Application (pre‑5.36.00.00).
Real-world impact
An attacker can repeatedly replay captured requests to create new admin access and refresh tokens, giving them full control over the appliance or application without any authentication.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable remotely without authentication, allows complete compromise of confidentiality, integrity, and availability, and can be abused repeatedly because there is no nonce or time limit on requests.
What to do about it
- 01Upgrade the Dell SCG 5.0 Appliance to version 5.36.00.16 or later.
- 02Upgrade the Dell SCG 5.0 Application to version 5.36.00.00 or later.
NVD-referenced vendor advisory
Timeline
- Sep 9, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 9, 2026 · 4d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- dell.com/support/kbdoc/en-in/0005034…vendor advisory