ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
ZDI discloses CVE-2026-66148, a command injection local privilege escalation in SonicWall GMS Virtual Appliance rated CVSS 7.8.
ZDI-26-531 describes a command injection vulnerability in the SonicWall GMS Virtual Appliance interface that allows local attackers to escalate privileges. Exploitation requires the attacker to first execute low-privileged code on the target system. ZDI assigned a CVSS score of 7.8, tracked as CVE-2026-66148.
- Command injection in SonicWall GMS Virtual Appliance interface
- Local privilege escalation requiring existing low-privileged access
- CVSS 7.8, tracked as CVE-2026-66148
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66148 | Authenticated Command Injection in SonicWall GMS CLI Allows Root Privilege Escalation CVE-2026-66148 is an authenticated command injection flaw (CWE-94) in the Command-Line Interface of SonicWall's GMS (Global Management System) Virtual Appliance, affecting GMS CLI 9.5.1 (Build 9510.1044) and all earlier versions. A low-privileged authenticated user can inject operating-system commands through the CLI/interface, which are then executed without proper sanitization. Because the CLI runs with elevated rights, the injected commands execute as root, giving the attacker full control of the management appliance — a local privilege escalation to the highest privilege level. Organizations running affected GMS builds — typically enterprises and managed service providers that use GMS Virtual Appliances to centrally manage SonicWall firewalls — are affected. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 1.2%, so exploitation is not currently known to be occurring. Do: Upgrade GMS Virtual Appliances to a fixed release per SonicWall's advisory — any build newer than 9.5.1 (Build 9510.1044) — and verify the running build in the appliance interface. Until patched, restrict CLI and appliance login access to trusted administrators with least-privilege accounts, since exploitation requires authenticated low-privileged access. Monitor appliance logs for unexpected local command execution, and treat management appliances as high-value targets given the root-level access a successful exploit grants. | 6.3 | 1% |
| moderate≈ low tens of thousands of GMS Virtual Appliance deployments worldwide (estimate; no public install-base figure provided) |
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66148.
This source does not provide full text. Read it at zerodayinitiative.com.