Description
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
Published: 2026-09-04
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to SuperAdmin
Action: Apply Patch
AI Analysis

Impact

A missing authorization check in the SonicWall Network Security Manager (NSM) On‑Prem Management interface allows a user who has been granted a lower‑privileged Admin role to acquire SuperAdmin privileges. This escalation grants the attacker the authority associated with a SuperAdmin account, enabling full management of the system as permitted by that role.

Affected Systems

SonicWall Network Security Manager (NSM) On‑Prem Management interface. Any deployment of this product that has not yet applied the vendor’s patch for the missing authorization flaw is vulnerable. Version information is not specified in the advisory, so all impacted installations are presumed affected until verified otherwise by the vendor.

Risk and Exploitability

The vulnerability is classified as a missing authorization flaw (CWE‑862). Exploitation requires the attacker to already have access to the management interface as a lower‑privileged Admin. It is inferred that the attack vector involves remote or internal access to the management interface. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the nature of the flaw implies a severe risk if left unpatched. The CVSS score of 9.1 indicates a critical severity.

Generated by OpenCVE AI on September 4, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest SonicWall Network Security Manager firmware or patch that addresses the missing authorization issue as soon as possible.
  • Apply least privilege principles by limiting the number of low‑privileged Admin accounts and removing unnecessary permissions from each account.
  • Audit management interface logs regularly for signs of unauthorized privilege escalation attempts and review admin account activity to detect potential misuse.

Generated by OpenCVE AI on September 4, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall network Security Manager
Vendors & Products Sonicwall
Sonicwall network Security Manager

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Missing Authorization in SonicWall Network Security Manager On‑Prem Management Interface

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
Weaknesses CWE-862
References

Subscriptions

Sonicwall Network Security Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-09-04T19:49:34.157Z

Reserved: 2026-08-24T09:38:46.404Z

Link: CVE-2026-78328

cve-icon Vulnrichment

Updated: 2026-09-04T19:49:25.869Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T19:17:27.463

Modified: 2026-09-08T19:12:59.557

Link: CVE-2026-78328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:15:14Z

Weaknesses