Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 - CVE-2026-83548
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
The vulnerability exists due to server-side request forgery in the SMA1000 Appliance Work Place interface when handling requests through an unintended alternate access path. A remote attacker can send crafted requests to gain unauthorized access to sensitive functionality and perform unauthorized operations.
The issue is pre-authentication and involves an unintended forward-proxy behavior.
Note, the vulnerability is being actively exploited in the wild.