← All Advisories

SonicWall Network Security Manager On-Prem Management Interface Passes Authenticated User Input to the OS Shell, Enabling Arbitrary Command Execution

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-78327

Key Details

CVECVE-2026-78327
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-78327
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-78327