Description
An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.
Published: 2026-08-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficient certificate validation flaw in the privileged communication workflow of SonicWall GMS allows an attacker who successfully performs a man‑in‑the‑middle (MitM) attack under controlled network conditions to perform unauthorized changes. This flaw can lead to integrity violations and may enable the attacker to modify or inject data through the privileged channel, potentially escalating privileges within the system.

Affected Systems

SonicWall GMS, particularly version 9.5.1 (Build 9510.1044) and earlier releases. The vulnerability is tied to the GMS application’s privileged communication components found in these affected versions.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.3, indicating high severity. Its EPSS score is 0.13%, suggesting a very low probability of exploitation, and it is not listed in CISA’s KEV catalog. Attacking this flaw requires a successful MitM intrusion with controlled network conditions, implying that the attack vector is network‑based and demands some level of network access or interception capability. If exploited, the attacker could alter system configuration or data, compromising confidentiality, integrity, and potentially availability of the GMS deployment.

Generated by OpenCVE AI on August 12, 2026 at 15:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SonicWall GMS to the latest available version that addresses the certificate validation issue.
  • If an immediate update is not possible, implement network segmentation and restrict privileged communication paths to trusted subnets to limit exposure to MitM attacks.
  • Deploy network intrusion detection or monitoring tools to detect and alert on anomalous TLS traffic that may indicate a MitM effort.

Generated by OpenCVE AI on August 12, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall gms
Vendors & Products Sonicwall
Sonicwall gms

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Insufficient Certificate Validation Allowing Unauthorized Changes in SonicWall GMS

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.
Weaknesses CWE-295
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-12T14:47:58.659Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66154

cve-icon Vulnrichment

Updated: 2026-08-11T21:10:23.754Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T21:17:49.600

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:41Z

Weaknesses
  • CWE-295

    Improper Certificate Validation