Cross-site scripting in SonicWall SMA 1000 - CVE-2026-102258

 

Cross-site scripting in SonicWall SMA 1000 - CVE-2026-102258

Published: October 6, 2026


Vulnerability identifier: #VU153403
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-102258
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript code in the Appliance Management Console.

The vulnerability exists due to stored cross-site scripting in the SMA1000 Appliance Management Console (AMC) when handling stored content. A remote privileged user can store malicious JavaScript code to execute arbitrary JavaScript code in the Appliance Management Console.

Exploitation requires an administrator account and specific conditions that the advisory does not describe.


Affected software

SonicWall SMA 1000

How to mitigate CVE-2026-102258

Install security update from vendor's website.

SonicWall SMA 1000 - addressed in versions 12.4.3-03670, 12.5.0-03082

External References

Related Security Bulletins