CVE-2026-66148 is an authenticated command injection flaw (CWE-94) in the Command-Line Interface of SonicWall's GMS (Global Management System) Virtual Appliance, affecting GMS CLI 9.5.1 (Build 9510.1044) and all earlier versions. A low-privileged authenticated user can inject operating-system commands through the CLI/interface, which are then executed without proper sanitization. Because the CLI runs with elevated rights, the injected commands execute as root, giving the attacker full control of the management appliance — a local privilege escalation to the highest privilege level. Organizations running affected GMS builds — typically enterprises and managed service providers that use GMS Virtual Appliances to centrally manage SonicWall firewalls — are affected. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 1.2%, so exploitation is not currently known to be occurring.
What to do: Upgrade GMS Virtual Appliances to a fixed release per SonicWall's advisory — any build newer than 9.5.1 (Build 9510.1044) — and verify the running build in the appliance interface. Until patched, restrict CLI and appliance login access to trusted administrators with least-privilege accounts, since exploitation requires authenticated low-privileged access. Monitor appliance logs for unexpected local command execution, and treat management appliances as high-value targets given the root-level access a successful exploit grants.
moderate≈ low tens of thousands of GMS Virtual Appliance deployments worldwide (estimate; no public install-base figure provided) — GMS is SonicWall's central management platform typically deployed as one appliance per enterprise or MSSP rather than per firewall, so its installed base is orders of magnitude smaller than SonicWall's million-plus firewall fleet and is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.
ZDI discloses CVE-2026-66148, a command injection local privilege escalation in SonicWall GMS Virtual Appliance rated CVSS 7.8.
ZDI-26-531 describes a command injection vulnerability in the SonicWall GMS Virtual Appliance interface that allows local attackers to escalate privileges. Exploitation requires the attacker to first execute low-privileged code on the target system. ZDI assigned a CVSS score of 7.8, tracked as CVE-2026-66148.