Pre-authentication SSRF Vulnerability in SonicWall SMA1000 Appliance
CVE-2026-102255

Currently unrated

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
7 October 2026

Badges

📰 News Worthy

What is CVE-2026-102255?

A Pre-authentication Server-Side Request Forgery (SSRF) vulnerability has been identified in the SonicWall SMA1000 Appliance's Work Place interface. This issue arises from an unintended alternate access path that could be exploited by a remote unauthenticated attacker. By manipulating this path, the attacker may direct the appliance to execute requests on their behalf, potentially exposing internal functionalities and allowing for unauthorized operations within the appliance.

Affected Version(s)

SMA1000 Linux 12.4.3-03526 (platform-hotfix) and older versions

SMA1000 Linux 12.5.0-02952 (platform-hotfix) and older versions

News Articles

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

4 hours ago

References

Timeline

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.