Authenticated Command Injection Vulnerability in GMS Command-Line Interface by SonicWall
CVE-2026-66148
6.3MEDIUM
What is CVE-2026-66148?
An authenticated command injection vulnerability has been discovered in SonicWall's GMS Command-Line Interface (CLI), specifically in version 9.5.1 (Build 9510.1044) and earlier. This flaw permits low-privileged local users to execute system commands with root privileges, posing significant security risks. It is crucial for organizations using affected versions to apply appropriate security measures and updates to mitigate any potential exploitation.
Affected Version(s)
GMS Linux 9.5.1 and earlier versions