CVE-2026-80172
Last modified
CVE-2026-80172 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Secure Connect Gateway | < 5.36.00.00 |
| Dell | Secure Connect Gateway | < 5.36.00.16 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-80172?
How severe is CVE-2026-80172?
How do I fix CVE-2026-80172?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80166Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…7.8
- CVE-2026-80167Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.5
- CVE-2026-80169Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…3.3
- CVE-2026-8017Side-channel information leakage in Media in Google Chrome p…3.1
- CVE-2026-80170Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…6.5
- CVE-2026-80171Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…4.7
- CVE-2026-80174Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.3
- CVE-2026-80175Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…3.3
- CVE-2026-80176Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…4.7
- CVE-2026-80177Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…6.5
- CVE-2026-80178Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…7.8
- CVE-2026-80179A flaw was found in jwcrypto. A remote attacker can send a s…5.9
Are you affected by CVE-2026-80172?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
