OS Command Injection in SonicWall SMA 1000 - CVE-2026-83549
Published: September 2, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary OS commands.
The vulnerability exists due to command injection in the SMA1000 Appliance Management Console (AMC) when processing input in specific conditions. A local user can send crafted input to execute arbitrary OS commands.
Exploitation is post-authentication and requires specific conditions.
Note, the vulnerability is being actively exploited in the wild.