Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-10-09
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Elevation of Privileges
Action: Apply Patch
AI Analysis

Impact

A missing authorization flaw in the Dell Secure Connect Gateway Policy Manager allows an attacker with low privileges who can reach the system remotely to gain higher level privileges. This vulnerability permits the attacker to manipulate configuration or data that should only be accessible by authorized users. The lack of proper checks on actions within the Policy Manager means an attacker can execute privileged commands without needing administrative credentials.

Affected Systems

Dell Secure Connect Gateway Policy Manager, any version earlier than 5.34.00.16. Users running these older builds are exposed to the missing authorization issue. The vulnerability applies to all deployments of the policy manager component that have remote access enabled.

Risk and Exploitability

The CVSS score of 4.3 indicates the weakness poses a medium risk overall. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not documented. Nevertheless, the attack vector is inferred to be remote access to the Policy Manager interface by an attacker with limited credentials; once accessed, privilege escalation can occur. Given the relatively low severity score but potential for significant impact if exploited, the risk remains moderate and warrants timely remediation.

Generated by OpenCVE AI on October 9, 2026 at 09:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the Dell security update that includes version 5.34.00.16 or later to eliminate the missing authorization flaw
  • If an update cannot be applied immediately, restrict remote administrative access to the Policy Manager to trusted networks or users
  • Continuously monitor audit logs for unauthorized attempts to access privileged functions and investigate any suspicious activity promptly

Generated by OpenCVE AI on October 9, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Dell Secure Connect Gateway Policy Manager Leading to Privilege Escalation

Fri, 09 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-09T08:16:01.809Z

Reserved: 2026-08-19T17:05:19.871Z

Link: CVE-2026-76769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:08.290

Modified: 2026-10-09T09:17:08.290

Link: CVE-2026-76769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses