ZeroHour

CVE-2026-66148

moderate

Authenticated Command Injection in SonicWall GMS CLI Allows Root Privilege Escalation

CVSS 3.1
6.3 medium
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-66148 is an authenticated command injection flaw (CWE-94) in the Command-Line Interface of SonicWall's GMS (Global Management System) Virtual Appliance, affecting GMS CLI 9.5.1 (Build 9510.1044) and all earlier versions. A low-privileged authenticated user can inject operating-system commands through the CLI/interface, which are then executed without proper sanitization. Because the CLI runs with elevated rights, the injected commands execute as root, giving the attacker full control of the management appliance — a local privilege escalation to the highest privilege level. Organizations running affected GMS builds — typically enterprises and managed service providers that use GMS Virtual Appliances to centrally manage SonicWall firewalls — are affected. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 1.2%, so exploitation is not currently known to be occurring.

What to do: Upgrade GMS Virtual Appliances to a fixed release per SonicWall's advisory — any build newer than 9.5.1 (Build 9510.1044) — and verify the running build in the appliance interface. Until patched, restrict CLI and appliance login access to trusted administrators with least-privilege accounts, since exploitation requires authenticated low-privileged access. Monitor appliance logs for unexpected local command execution, and treat management appliances as high-value targets given the root-level access a successful exploit grants.

Affected
SonicWall GMS Virtual Appliance — GMS Command-Line Interface (CLI)9.5.1 (Build 9510.1044) and all earlier versions
Estimated exposure
moderate≈ low tens of thousands of GMS Virtual Appliance deployments worldwide (estimate; no public install-base figure provided) — GMS is SonicWall's central management platform typically deployed as one appliance per enterprise or MSSP rather than per firewall, so its installed base is orders of magnitude smaller than SonicWall's million-plus firewall fleet and is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability

ZDI discloses CVE-2026-66148, a command injection local privilege escalation in SonicWall GMS Virtual Appliance rated CVSS 7.8.

ZDI-26-531 describes a command injection vulnerability in the SonicWall GMS Virtual Appliance interface that allows local attackers to escalate privileges. Exploitation requires the attacker to first execute low-privileged code on the target system. ZDI assigned a CVSS score of 7.8, tracked as CVE-2026-66148.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-66148