Description
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
Published: 2026-09-04
Score: 9.1 Critical
EPSS: 1.6% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An improper neutralization of special elements in user-supplied input allows an authenticated user with SuperAdmin privileges to inject arbitrary operating system commands via the On‑Prem Management interface of the SonicWall Network Security Manager. The injected commands are executed with the privileges of the underlying host, giving the attacker complete control over the device. This flaw enables the attacker to compromise confidentiality, integrity, and availability of the entire managed network.

Affected Systems

The vulnerability affects SonicWall Network Security Manager (NSM) On‑Prem installations. Specific affected versions are not enumerated in the advisory, so any current NSM deployment that still relies on the legacy On‑Prem interface should be reviewed.

Risk and Exploitability

The exploitation requires valid SuperAdmin credentials, so privileged access is a prerequisite. The EPSS score is 2%, and the lack of publicly disclosed exploits and the absence from the CISA KEV catalog indicate that widespread active exploitation is currently unlikely. Nevertheless, the potential impact is severe; once exploited, an attacker can execute arbitrary code on the host. Defensive measures should therefore be prioritized to prevent privileged users from having unnecessary exposure.

Generated by OpenCVE AI on September 5, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version of SonicWall Network Security Manager where the OS command injection flaw is fixed
  • Limit SuperAdmin access to a dedicated, isolated management network or VPN that is strictly monitored
  • Review and tighten credential management policies, ensuring that high‑privilege accounts are protected with strong authentication and regularly audited

Generated by OpenCVE AI on September 5, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall network Security Manager
Vendors & Products Sonicwall
Sonicwall network Security Manager

Sat, 05 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Remote Code Execution in SonicWall Network Security Manager On‑Prem Management Interface

Sat, 05 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection via SuperAdmin Privileges in SonicWall Network Security Manager

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection via SuperAdmin Privileges in SonicWall Network Security Manager
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
Weaknesses CWE-78
References

Subscriptions

Sonicwall Network Security Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-09-04T19:50:05.348Z

Reserved: 2026-08-24T09:38:44.377Z

Link: CVE-2026-78327

cve-icon Vulnrichment

Updated: 2026-09-04T19:49:59.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T19:17:27.347

Modified: 2026-09-08T19:12:59.557

Link: CVE-2026-78327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')