Stored Cross-Site Scripting Vulnerability in SonicWall Email Security Appliance
CVE-2026-3468

4.8MEDIUM

Key Information:

Vendor

Sonicwall

Vendor
CVE Published:
31 March 2026

What is CVE-2026-3468?

A vulnerability has been discovered in SonicWall Email Security Appliance that allows an authenticated remote attacker to inject and execute arbitrary JavaScript code. This occurs due to inadequate validation of user-supplied input during the web page generation process, posing a significant risk to the integrity and confidentiality of the affected system.

Affected Version(s)

Email Security Linux 10.0.34.8215 and earlier versions

Email Security Linux 10.0.34.8223 and earlier versions

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani of DigitalCanion SA - www.digitalcanion.com
.