Cross-site scripting in SonicWall SMA 1000 - CVE-2026-102258
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript code in the Appliance Management Console.
The vulnerability exists due to stored cross-site scripting in the SMA1000 Appliance Management Console (AMC) when handling stored content. A remote privileged user can store malicious JavaScript code to execute arbitrary JavaScript code in the Appliance Management Console.
Exploitation requires an administrator account and specific conditions that the advisory does not describe.