Multiple Cross-Site Scripting Vulnerabilities in SonicWall GMS Products
CVE-2026-66146

6.1MEDIUM

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-66146?

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in SonicWall's GMS 9.5.1 and earlier versions. These vulnerabilities enable remote attackers to inject and execute harmful JavaScript code in the user's browser, potentially compromising user sessions or exposing sensitive information. Proper validation and sanitization of user inputs are crucial to mitigate these vulnerabilities.

Affected Version(s)

GMS Windows 9.5.1 and earlier versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.