SB2026081137 - Multiple vulnerabilities in SonicWall GMS
Published: August 11, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Code Injection (CVE-ID: CVE-2026-66145)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read sensitive data and perform arbitrary file write.
The vulnerability exists due to code injection in GMS when processing crafted zip content via zipslip. A remote attacker can supply a specially crafted archive to read sensitive data and perform arbitrary file write.
2) Cross-site scripting (CVE-ID: CVE-2026-66146)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute javascript in a user's browser.
The vulnerability exists due to cross-site scripting in the GMS web interface when rendering web content. A remote user can inject a crafted script to execute javascript in a user's browser.
User interaction is required.
3) Code Injection (CVE-ID: CVE-2026-66147)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to command injection in the GMS Dispatcher Service when handling specially crafted requests. A remote attacker can send a specially crafted request to execute arbitrary code.
4) Code Injection (CVE-ID: CVE-2026-66148)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute system commands with root privileges.
The vulnerability exists due to command injection in the GMS Command-Line Interface (CLI) when processing crafted input. A remote user can submit crafted input to execute system commands with root privileges.
5) Improper Certificate Validation (CVE-ID: CVE-2026-66154)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to make unauthorized changes.
The vulnerability exists due to improper certificate validation in a privileged communication workflow when operating under a machine-in-the-middle position on the local network. A remote attacker can intercept and manipulate communication to make unauthorized changes.
Exploitation requires controlled network conditions.
6) Deserialization of Untrusted Data (CVE-ID: CVE-2026-18634)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to deserialization of untrusted data in a GMS service when handling serialized objects. A remote attacker can interact with the affected service to perform unauthorized actions.
Remediation
Install update from vendor's website.