Description
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Published: 2026-08-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated remote code execution flaw has been identified in SonicWall GMS 9.5.1 (build 9510.1044) and all earlier releases; the defect, a Code Injection weakness (CWE‑94), allows a malicious actor to supply a specially crafted ZIP file that exploits a zipslip path‑traversal bug, enabling arbitrary file writes and direct reading of sensitive data on the device, effectively granting full control over the appliance.

Affected Systems

The vulnerability affects SonicWall GMS versions up to and including 9.5.1 build 9510.1044. Any GMS appliance running a release in this range without an applicable patch is therefore vulnerable.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, while the EPSS score of less than 1 % suggests a low probability of exploitation relative to other threats. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated remote attacker who embeds and uploads a malicious ZIP archive to the vulnerable GMS, triggering the zipslip exploit and achieving arbitrary file writes.

Generated by OpenCVE AI on August 12, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch that eliminates the zipslip vulnerability.
  • If the patch cannot be deployed immediately, isolate the GMS appliance from untrusted networks and limit inbound connections to trusted internal hosts only.
  • Disable or tightly restrict the upload and processing of ZIP archives on the appliance to close the exploitation path until a patch is applied.

Generated by OpenCVE AI on August 12, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall gms
Vendors & Products Sonicwall
Sonicwall gms

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Zipslip Path Traversal Enabling Remote Code Execution in SonicWall GMS

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Weaknesses CWE-94
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-12T14:46:28.752Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66145

cve-icon Vulnrichment

Updated: 2026-08-11T20:22:03.051Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T20:18:37.717

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:47Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')