CVE-2026-78327
largeOS Command Injection RCE in SonicWall NSM On-Prem Management (SuperAdmin required)
CVE-2026-78327 is an OS command injection flaw (CWE-78) in the SonicWall Network Security Manager (NSM) On-Prem Management interface, where special elements passed to the operating system are improperly neutralized. An authenticated attacker holding SuperAdmin privileges can reach the network-accessible management interface and inject arbitrary commands that execute on the underlying host, yielding full remote code execution. Successful exploitation grants control over the NSM management server itself, and the scope-changed CVSS vector (S:C) indicates compromise could extend beyond the vulnerable component. Only organizations running the on-premises NSM management deployment are affected; cloud-managed NSM customers and accounts without SuperAdmin privileges are not exposed to this specific attack path. As of now there is no evidence of exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a ~1.6% chance of exploitation within 30 days.
What to do: Monitor SonicWall's security advisories and apply the vendor's patch for the NSM On-Prem release as soon as it is published. In the interim, restrict access to the on-prem NSM management interface to trusted management networks or VPN, and audit which accounts hold SuperAdmin privileges since those credentials are required for exploitation. Review NSM host logs for unexpected command execution or administrative activity from unusual sources.
| SonicWall Network Security Manager (NSM) On-Prem — Management interface | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.