Description
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
Published: 2026-08-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This Cross‑Site Scripting vulnerability in SonicWall GMS 9.5.1 (Build 9510.1044) and earlier permits a remote attacker to inject and execute arbitrary JavaScript in the victim’s browser. Attackers could hijack the user session, steal credentials, or deliver phishing content. The flaw is a classic CWE‑79 incident.

Affected Systems

Impacting SonicWall GMS versions 9.5.1 and older. All deployments of SonicWall GMS with build 9510.1044 or earlier are vulnerable.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate overall risk. The EPSS score of less than 1% shows very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to visit a malicious link or otherwise cause the GMS interface to render attacker‑supplied input. The attack vector is remote through crafted input to the GMS web interface.

Generated by OpenCVE AI on August 12, 2026 at 20:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SonicWall GMS to a version released after 9.5.1 that contains the XSS fix.
  • Configure the GMS product to enforce strict input validation and sanitization on all user‑supplied fields.
  • Deploy an application firewall or enable browser‑based XSS protections such as a Content Security Policy to block injected scripts.

Generated by OpenCVE AI on August 12, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall gms
Vendors & Products Sonicwall
Sonicwall gms

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in SonicWall GMS Allowing Remote Execution of JavaScript

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-11T20:13:29.530Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66146

cve-icon Vulnrichment

Updated: 2026-08-11T20:13:25.427Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T20:18:37.837

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:45Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')