CVE-2026-80238
Last modified
CVE-2026-80238 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Secure Connect Gateway | < 5.36.00.00 |
| Dell | Secure Connect Gateway | < 5.36.00.16 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-80238?
How severe is CVE-2026-80238?
How do I fix CVE-2026-80238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80231A flaw in libcurl makes it wrongly reuse an existing HTTPS c…7.5
- CVE-2026-80233CAYIN CMS-WS, CMS-SE, and SMP series products developed by C…7.2
- CVE-2026-80234CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a…5.3
- CVE-2026-80235EFence developed by Thinking Software Technology has an Arbi…9.8
- CVE-2026-80236Efence developed by Thinking Software Technology has a SQL I…8.2
- CVE-2026-80237EFence developed by Thinking Software Technology has an Arbi…8.8
- CVE-2026-80239Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…2.4
- CVE-2026-8024A remote, unauthenticated attacker may exploit a deserializa…9.8
- CVE-2026-8025Improper neutralization of special elements used in an SQL c…9.8
- CVE-2026-80253An improper physical access control issue exists in ShizenBo…7
- CVE-2026-80254Authorization bypass through user-controlled key issue exist…7.1
- CVE-2026-80255A `Set-Cookie:` header using tab (horizontal tab, ASCII code…7.5
Are you affected by CVE-2026-80238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
