Insufficient Certificate Validation in GMS Application by SonicWall
CVE-2026-66154
8.3HIGH
What is CVE-2026-66154?
A vulnerability affecting SonicWall's GMS application versions 9.5.1 and earlier has been discovered, where insufficient validation of certificates in a privileged communication workflow could lead to unauthorized alterations. Under specific network conditions, this weak point may permit Man-in-the-Middle (MitM) attacks, allowing attackers to exploit the situation and manipulate communications without detection. Organizations using these affected versions should prioritize addressing this vulnerability to enhance their security posture.
Affected Version(s)
GMS Linux 9.5.1 and earlier versions