Description
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper control of code generation in the SonicWall Email Security appliance. An authenticated user who can access the SonicWall Email Security restricted command line interface can inject arbitrary operating‑system commands. The injected commands execute with root privileges via SNMP, effectively giving the attacker full control of the device. The weakness is a classic code injection flaw (CWE‑94).

Affected Systems

The affected product is SonicWall Email Security, with all versions that expose the restricted CLI and SNMP interface potentially vulnerable. No specific version ranges are listed in the CNA data, so apply the fix to all deployments that have the CLI enabled.

Risk and Exploitability

The CVSS score of 7.8 reflects a high‑severity flaw. Because the attack requires valid authentication to the restricted CLI, the risk is confined to users or processes that have legitimate access. Once authenticated, the attacker can execute arbitrary commands as root, providing complete compromise of the appliance. The EPSS score is not available and the vulnerability is not noted in CISA KEV, but the high CVSS and the root‑level impact suggest a strong likelihood of exploitation if an attacker gains CLI access. The flaw can be exploited over SNMP, indicating a network‑based attack vector that leverages legitimate administrative channels.

Generated by OpenCVE AI on August 12, 2026 at 14:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware update from SonicWall that addresses the CLI command injection flaw.
  • Restrict or disable the restricted CLI and SNMP service on the appliance to limit authenticated users’ ability to inject commands.
  • Enable detailed logging and alerts for SNMP command execution and audit logs to detect and respond to unauthorized activity.

Generated by OpenCVE AI on August 12, 2026 at 14:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection via Restricted CLI in SonicWall Email Security

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall email Security
Vendors & Products Sonicwall
Sonicwall email Security

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Weaknesses CWE-94
References

Subscriptions

Sonicwall Email Security
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-12T04:00:40.772Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66150

cve-icon Vulnrichment

Updated: 2026-08-11T21:06:58.101Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T21:17:49.497

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T14:30:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')