Description
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Published: 2026-08-11
Score: 9.4 Critical
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated command injection flaw in the SonicWall GMS Dispatcher Service allows an attacker to execute arbitrary system commands on the underlying operating system. The vulnerability arises when the service processes specially crafted requests without proper input validation, leading to remote code execution. This weakness can compromise confidentiality, integrity, and availability of the affected system, potentially giving attackers full control over the compromised device.

Affected Systems

SonicWall GMS 9.5.1 and all earlier releases of the GMS platform are affected. The flaw resides specifically within the Dispatcher Service component of the product.

Risk and Exploitability

The CVSS score of 9.4 classifies this as Critical, indicating a high likelihood of success and impact. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no confirmed exploitation evidence yet. The attack vector is remote, leveraging unauthenticated HTTP requests to the Dispatcher Service. Because the endpoint is reachable from external networks, the condition for exploitation is minimal, enabling an attacker to trigger the flaw with no prior credential or privilege.

Generated by OpenCVE AI on August 13, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SonicWall GMS firmware or patch that fixes the Dispatcher Service command injection flaw.
  • If an update is not immediately available, restrict or disable the Dispatcher Service endpoint to prevent external access, or limit it to a trusted internal network segment.
  • Implement network segmentation and firewalls to block unsolicited traffic to the GMS Dispatcher Service.
  • Monitor system logs for anomalous command execution patterns to detect potential exploitation.

Generated by OpenCVE AI on August 13, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall gms
Vendors & Products Sonicwall
Sonicwall gms

Thu, 13 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command Injection in SonicWall GMS Dispatcher Service

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command Injection in SonicWall GMS Dispatcher Service

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Weaknesses CWE-94
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-12T14:46:43.933Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66147

cve-icon Vulnrichment

Updated: 2026-08-11T21:11:48.591Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T21:17:49.173

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:44Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')