CVE-2026-78339: CWE-732: Incorrect Permission Assignment for Critical Resource in Dell Secure Connect Gateway (SCG) Policy Manager
Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, and Unauthorized access.
CVSS v3.1
Score 6.3medium
Affected software
Dell
Secure Connect Gateway (SCG) Policy Manager
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-78339 describes an incorrect permission assignment for a critical resource in Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16. This vulnerability enables a low privileged attacker with local access to exploit the flaw, potentially leading to unauthorized access, information disclosure, and bypass of protection mechanisms. The CVSS v3.1 base score is 6.3, reflecting medium severity with attack vector local, high attack complexity, low privileges required, no user interaction, and impacts on confidentiality and integrity but not availability.
Potential Impact
An attacker with low privileges and local access could exploit this vulnerability to gain unauthorized access to critical resources, disclose sensitive information, and bypass security protections within the Dell SCG Policy Manager. This could compromise confidentiality and integrity of the system but does not affect availability.
Mitigation Recommendations
No explicit patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the Dell vendor advisory for current remediation guidance. Until a fix is available, restrict local access to trusted users only and monitor for suspicious activity related to permission escalations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- dell
- Date Reserved
- 2026-08-24T11:06:27.230Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac8b88f2cdf04f65646b76b
Added to database: 10/09/2026, 09:49:03 UTC
Last enriched: 10/09/2026, 10:03:35 UTC
Last updated: 10/09/2026, 18:57:32 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.