GNU tar flaw allows bypassing security measures

Published September 11, 2026

Dell Secure Connect Gateway has a CERT-Bund advisory for CVE-2026-5704 in versions before 5.36.00.16. A local attacker can exploit a vulnerability in GNU tar to bypass security measures.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 5.36.00.16Fix recorded 3 days ago
Affected versions
before 5.36.00.16
Affects
Dell Secure Connect Gateway+3 more
Exploited
Not confirmedNo confirmation recorded

How it works

A local attacker can exploit a vulnerability in GNU tar to bypass security measures.

What to do

Check your Dell Secure Connect Gateway version. If it is before 5.36.00.16, this advisory applies.

Update Dell Secure Connect Gateway to 5.36.00.16 or newer.

Technical details

Affected software: Dell Secure Connect Gateway, Linux, UNIX, Windows

A local attacker can exploit a vulnerability in GNU tar to bypass security measures. The advisory tracks CVE-2026-5704. In CERT-Bund's CSAF data, affected versions are before 5.36.00.16, and the fixed version is 5.36.00.16. Affected operating systems listed by CERT-Bund: Linux, UNIX, Windows.