天下漏洞,尽知其名
MEDIUM

CVE-2026-78026 Dell SCG Policy Manager 授权绕过漏洞

影响低权限远程攻击者可越权提升权限

AI 研判

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前版本存在授权绕过漏洞(CVE-2026-78026),属于通过用户可控键值实现的授权绕过(Authorization Bypass Through User-Controlled Key)。攻击者利用该缺陷可绕过权限校验,实现权限提升。

影响范围

Dell Secure Connect Gateway Policy Manager

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前的版本受影响,具体受影响版本范围以 Dell 官方公告为准。

漏洞详情

漏洞类型为授权绕过(越权),成因在于系统对用户可控的键值(如对象标识符)未做充分的归属与权限校验,导致低权限用户可访问或操作本应属于更高权限的资源。远程低权限攻击者可通过构造特定请求利用该缺陷,从而提升自身权限。

利用条件与风险

利用需攻击者具备远程访问能力并拥有低权限账户,CVSS 4.3 属中危,成功利用可导致权限提升,实际风险取决于目标暴露面与账户获取难度。

修复建议

建议升级至 Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 或更高版本;临时缓解措施可参考 Dell 官方安全公告,暂无公开信息。

原始情报

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.