ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability
ZDI advisory ZDI-26-532 discloses CVE-2026-66149, a command injection in SonicWall Email Security updateNetIf allowing local privilege escalation (CVSS 7.8).
SonicWall Email Security contains a command injection flaw in the updateNetIf routine, tracked as CVE-2026-66149 with CVSS 7.8. A local attacker must first obtain the ability to execute low-privileged code on the target system in order to escalate privileges. The vulnerability was disclosed via ZDI advisory ZDI-26-532.
- Command injection in updateNetIf routine, CVE-2026-66149, CVSS 7.8
- Local privilege escalation requires prior low-privileged code execution
- Affects SonicWall Email Security deployments
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66149 | Authenticated CLI command injection yields root on SonicWall Email Security CVE-2026-66149 is a command injection flaw (CWE-94) in the SonicWall Email Security appliance, in the network interface update routine (updateNetIf per the ZDI advisory) that handles the netmask parameter. An attacker who is already authenticated and has access to the appliance's restricted CLI can pass a malicious netmask value, causing arbitrary operating system commands to be injected and executed. Because the injected commands run as root, the attacker gains full privilege escalation from the limited CLI context to complete control of the appliance, with high impact on confidentiality, integrity, and availability. All organizations running the affected SonicWall Email Security appliance are exposed, though only to users or attackers who can already reach the restricted CLI, making this primarily a local privilege escalation rather than a remote attack. There is currently no known public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.2%, indicating no confirmed exploitation in the wild at this time. Do: Update SonicWall Email Security appliances to the fixed release identified in SonicWall's PSIRT advisory (version numbers not provided in the available data), prioritizing appliances where non-administrators or scripts have restricted-CLI access. Until patched, limit restricted-CLI access to trusted administrators only and audit local accounts and any automation that touches interface configuration. Since this requires local authenticated access and there is no known exploitation, treat it as a high-severity but routine patching item rather than an emergency. | 7.8 | <1% |
| moderatelikely on the order of tens of thousands of appliances deployed at organizations worldwide (estimate; SonicWall has not published an Email Security… |
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66149.
This source does not provide full text. Read it at zerodayinitiative.com.