Path Traversal Vulnerability in SonicWall NetExtender Linux Client
CVE-2026-66152

8.8HIGH

Key Information:

Vendor

Sonicwall

Vendor
CVE Published:
25 August 2026

What is CVE-2026-66152?

A path traversal vulnerability exists in the SonicWall NetExtender Linux client that could enable attackers to write arbitrary files with root privileges. By leveraging this flaw, an attacker could manipulate the application to gain unauthorized access to the file system, posing significant security risks. Users are advised to review the vendor advisory and apply any available patches or updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

NetExtender Linux 10.3.5 and earlier versions

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.