ID:13066 - Exploit for OS Command Injection in SonicWall SMA 1000 - CVE-2026-83549

 
Main Vulnerability Database Exploits ID:13066 - Exploit for OS Command Injection in SonicWall SMA 1000 - CVE-2026-83549

ID:13066 - Exploit for OS Command Injection in SonicWall SMA 1000 - CVE-2026-83549

Published: September 9, 2026


Vulnerability identifier: #VU146660
Vulnerability risk: High
CVE-ID: CVE-2026-83549
CWE-ID: CWE-78
Exploitation vector: Remote access
Vulnerable software:
SonicWall SMA 1000

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to execute arbitrary OS commands.

The vulnerability exists due to command injection in the SMA1000 Appliance Management Console (AMC) when processing input in specific conditions. A local user can send crafted input to execute arbitrary OS commands.

Exploitation is post-authentication and requires specific conditions.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install security update from vendor's website.