Insufficient Certificate Validation in GMS Application by SonicWall
CVE-2026-66154

8.3HIGH

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-66154?

A vulnerability affecting SonicWall's GMS application versions 9.5.1 and earlier has been discovered, where insufficient validation of certificates in a privileged communication workflow could lead to unauthorized alterations. Under specific network conditions, this weak point may permit Man-in-the-Middle (MitM) attacks, allowing attackers to exploit the situation and manipulate communications without detection. Organizations using these affected versions should prioritize addressing this vulnerability to enhance their security posture.

Affected Version(s)

GMS Linux 9.5.1 and earlier versions

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.