SB2026100662 - Multiple vulnerabilities in SonicWall SMA 1000
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-102255)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N]
The vulnerability allows a remote attacker to access internal functionality and perform unauthorized operations.
The vulnerability exists due to an unintended alternate access path in the SMA1000 Appliance Work Place interface when handling requests. A remote attacker can abuse this path to direct the appliance to issue requests on their behalf to access internal functionality and perform unauthorized operations.
2) OS Command Injection (CVE-ID: CVE-2026-102256)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an OS command in the SMA1000 appliance when handling OS commands. A local user can inject arbitrary OS commands to execute arbitrary code.
3) Path traversal (CVE-ID: CVE-2026-102257)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to path traversal in the SMA1000 Appliance Management Console (AMC) interface when extracting archive files. A remote privileged user can supply a specially crafted archive that causes files to be extracted outside the intended destination directory to execute arbitrary code.
4) Cross-site scripting (CVE-ID: CVE-2026-102258)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript code in the Appliance Management Console.
The vulnerability exists due to stored cross-site scripting in the SMA1000 Appliance Management Console (AMC) when handling stored content. A remote privileged user can store malicious JavaScript code to execute arbitrary JavaScript code in the Appliance Management Console.
Exploitation requires an administrator account and specific conditions that the advisory does not describe.
Remediation
Install update from vendor's website.