ZeroHour

CVE-2026-81939

moderate

Zip Slip path traversal in SonicWall Network Security Manager On-Prem

CVSS 3.1
9.1 critical
EPSS
<1%p52
Published
()
Modified
AI analysis

A Zip Slip path-traversal flaw (CWE-22) exists in the file upload and archive-processing functionality of SonicWall Network Security Manager (NSM) On-Prem, the on-premises central management platform for SonicWall firewalls. An attacker who has obtained high-privileged (administrator-level) access to the NSM interface uploads a specially crafted archive whose entries contain traversal paths, causing files to be extracted outside the intended destination directory. The CVSS scoring (scope changed, high confidentiality and integrity impact) indicates the out-of-directory writes can affect components beyond the upload function, so arbitrary file write with the service's privileges and potential follow-on code execution on the NSM server is plausible. Only organizations running the on-premises NSM deployment are affected; there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.7%, so no confirmed exploitation is currently known.

What to do: Monitor the SonicWall PSIRT advisory for CVE-2026-81939 and upgrade NSM On-Prem to the fixed release as soon as it is published, since no version numbers are available in the current data. Until patched, restrict administrator access to the NSM web interface to trusted management networks or VPN, limit which administrative accounts can upload archives, and review recent file-upload activity for signs of crafted archives. Internet-exposed NSM consoles should be prioritized for both mitigation and upgrade.

Affected
SonicWall Network Security Manager (NSM) On-Prem
Estimated exposure
moderatelikely on the order of thousands to low tens of thousands of on-prem NSM management servers worldwide — NSM On-Prem is a centralized management console typically deployed once per organization managing SonicWall firewalls, and while SonicWall's appliance installed base is large, the on-prem NSM subset (many customers use the cloud-hosted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.