CVE-2026-78328
largeMissing Authorization Privilege Escalation in SonicWall NSM On-Prem Management
A missing authorization check (CWE-862) in the management interface of SonicWall Network Security Manager (NSM) On-Prem allows a lower-privileged Admin account to escalate to SuperAdmin. The flaw is triggered over the network by a user who already holds the Admin role, whose management requests are not properly authorized by the interface. A successful attacker gains full SuperAdmin control of the NSM management server, with high confidentiality, integrity and availability impact (CVSS 9.1, changed scope), which typically also means control over the SonicWall firewall fleet that server manages. Only organizations running NSM On-Prem are affected, and exploitation requires an existing (or compromised) lower-privileged Admin account rather than unauthenticated access. There are no known public exploits, proofs of concept, or in-the-wild exploitation; the flaw is not in CISA's KEV catalog and the 30-day EPSS probability is 0.5%.
What to do: Apply the patched NSM On-Prem release identified in SonicWall's security advisory (fixed version not specified in the data available here). Until patching, restrict access to the NSM management interface to trusted management networks/VPN, minimize the number of users holding the Admin role, and review NSM audit logs for unexpected SuperAdmin-level account or privilege changes. Prioritize remediation where multiple operators share Admin credentials or where the management interface is reachable by semi-trusted users.
| SonicWall Network Security Manager (NSM) On-Prem - Management interface | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.