AI analysis
CVE-2026-102255 is a pre-authentication server-side request forgery flaw in the Work Place interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (CWE-441 and CWE-918). A remote unauthenticated attacker can abuse that path so the appliance issues requests on their behalf, reaching internal functionality and performing unauthorized operations. Impact is directed requests and unauthorized internal operations from the gateway, not a confirmed remote code execution outcome in the supplied description. SonicWall SMA1000 secure-access gateways that expose the Work Place interface are affected; no version range is stated in the data. There is no public proof of concept and it is not listed in CISA KEV, so exploitation is none known; CVSS is not yet scored, though vendor reporting describes it as maximum severity and a fix has been announced.
What to do: Apply SonicWall’s SMA1000 firmware fix for CVE-2026-102255 as soon as it is available for your build; the supplied data does not name a fixed version. Until patched, restrict the Work Place interface to trusted management networks and watch the appliance for unexpected outbound requests or access to internal services.
Affected
| SonicWall SMA1000 Appliance (Work Place interface) | — |
Estimated exposure
moderate≈1,000–10,000 internet-exposed appliances (estimate) — Order-of-magnitude estimate from typical public-scan exposure and enterprise deployment of SonicWall SMA SSL-VPN gateways (usually one or a few internet-facing appliances per organization); not a measured census.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.