SB2026081137 - Multiple vulnerabilities in SonicWall GMS



SB2026081137 - Multiple vulnerabilities in SonicWall GMS

Published: August 11, 2026

Security Bulletin ID SB2026081137
CSH Severity
High
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 33% Medium 17% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Code Injection (CVE-ID: CVE-2026-66145)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read sensitive data and perform arbitrary file write.

The vulnerability exists due to code injection in GMS when processing crafted zip content via zipslip. A remote attacker can supply a specially crafted archive to read sensitive data and perform arbitrary file write.


2) Cross-site scripting (CVE-ID: CVE-2026-66146)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute javascript in a user's browser.

The vulnerability exists due to cross-site scripting in the GMS web interface when rendering web content. A remote user can inject a crafted script to execute javascript in a user's browser.

User interaction is required.


3) Code Injection (CVE-ID: CVE-2026-66147)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to command injection in the GMS Dispatcher Service when handling specially crafted requests. A remote attacker can send a specially crafted request to execute arbitrary code.


4) Code Injection (CVE-ID: CVE-2026-66148)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute system commands with root privileges.

The vulnerability exists due to command injection in the GMS Command-Line Interface (CLI) when processing crafted input. A remote user can submit crafted input to execute system commands with root privileges.


5) Improper Certificate Validation (CVE-ID: CVE-2026-66154)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to make unauthorized changes.

The vulnerability exists due to improper certificate validation in a privileged communication workflow when operating under a machine-in-the-middle position on the local network. A remote attacker can intercept and manipulate communication to make unauthorized changes.

Exploitation requires controlled network conditions.


6) Deserialization of Untrusted Data (CVE-ID: CVE-2026-18634)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to deserialization of untrusted data in a GMS service when handling serialized objects. A remote attacker can interact with the affected service to perform unauthorized actions.


Remediation

Install update from vendor's website.