Insecure Handling of Serialized Objects in GMS Application by SonicWall
CVE-2026-18634

8.4HIGH

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-18634?

The GMS application from SonicWall, specifically version 9.5.1 (Build 9510.1044) and earlier, contains a vulnerability related to the insecure handling of serialized objects. This flaw allows local attackers who can interact with the service to exploit this insecurity, potentially enabling them to execute unauthorized actions through the affected component. Organizations using this software should take immediate steps to mitigate this risk by applying available updates or patches.

Affected Version(s)

GMS Linux 9.5.1 and earlier versions

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.