Improper Neutralization of HTTP Headers for Scripting Syntax in SonicOS - CVE-2026-0516

 

Improper Neutralization of HTTP Headers for Scripting Syntax in SonicOS - CVE-2026-0516

Published: August 6, 2026


Vulnerability identifier: #VU141057
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0516
CWE-ID: CWE-644
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect firewall management users to arbitrary web domains.

The vulnerability exists due to improper neutralization of HTTP headers for scripting syntax in the SonicOS web management interface when handling HTTP requests with a manipulated Host header. A remote attacker can send a specially crafted request to redirect firewall management users to arbitrary web domains.

User interaction is required for a firewall management user to follow the malicious redirection.


Affected software

SonicOS

How to mitigate CVE-2026-0516

Install security update from vendor's website.

SonicOS - update to 8.2.2-8015

External References

Related Security Bulletins