Stored Cross-Site Scripting Vulnerability in SMA1000 Appliance Management Console
CVE-2026-102258

Currently unrated

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-102258?

A vulnerability has been recognized in the SMA1000 Appliance Management Console, where a remote authenticated attacker, under specific circumstances, may be able to store and execute arbitrary JavaScript code. This occurs post-authentication, potentially compromising the integrity and security of the console, allowing attackers to manipulate functionalities or extract sensitive data without direct access.

Affected Version(s)

SMA1000 Linux 12.4.3-03526 (platform-hotfix) and older versions

SMA1000 Linux 12.5.0-02952 (platform-hotfix) and older versions

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani
.