OS Command Injection Vulnerability in SonicWall SMA1000 Appliance
CVE-2026-102256

Currently unrated

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-102256?

A vulnerability exists in SonicWall's SMA1000 appliance that allows authenticated remote attackers to exploit improper neutralization of special elements used in OS commands. In specific scenarios, an administrator could be tricked into executing arbitrary operating system commands, which may lead to remote code execution and compromise the security of the appliance.

Affected Version(s)

SMA1000 Linux 12.4.3-03526 (platform-hotfix) and older versions

SMA1000 Linux 12.5.0-02952 (platform-hotfix) and older versions

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.