Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 - CVE-2026-102255
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to access internal functionality and perform unauthorized operations.
The vulnerability exists due to an unintended alternate access path in the SMA1000 Appliance Work Place interface when handling requests. A remote attacker can abuse this path to direct the appliance to issue requests on their behalf to access internal functionality and perform unauthorized operations.