← All Advisories

Authenticated SonicWall Email Security CLI User Can Inject Arbitrary OS Commands as Root via SNMP

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-66150

Key Details

CVECVE-2026-66150
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-08-28
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-94 (Improper Control of Generation of Code ('Code Injection'))

What to Know

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-66150
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-66150