dell secure-connect-gateway CVE-2026-71178 is a vulnerability in Dell Secure Connect Gateway
Published on September 23, 2026

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-71178 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

Use of Non-Canonical URL Paths for Authorization Decisions

The software defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization.


Products Associated with CVE-2026-71178

Want to know whenever a new CVE is published for Dell Secure Connect Gateway? stack.watch will email you.

 

Affected Versions

Dell Secure Connect Gateway (SCG) Policy Manager: