ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 35CVE-2026-66148
AI summary · glm-5.3

ZDI discloses CVE-2026-66148, a command injection local privilege escalation in SonicWall GMS Virtual Appliance rated CVSS 7.8.

ZDI-26-531 describes a command injection vulnerability in the SonicWall GMS Virtual Appliance interface that allows local attackers to escalate privileges. Exploitation requires the attacker to first execute low-privileged code on the target system. ZDI assigned a CVSS score of 7.8, tracked as CVE-2026-66148.

  • Command injection in SonicWall GMS Virtual Appliance interface
  • Local privilege escalation requiring existing low-privileged access
  • CVSS 7.8, tracked as CVE-2026-66148

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-66148
Authenticated Command Injection in SonicWall GMS CLI Allows Root Privilege Escalation

CVE-2026-66148 is an authenticated command injection flaw (CWE-94) in the Command-Line Interface of SonicWall's GMS (Global Management System) Virtual Appliance, affecting GMS CLI 9.5.1 (Build 9510.1044) and all earlier versions. A low-privileged authenticated user can inject operating-system commands through the CLI/interface, which are then executed without proper sanitization. Because the CLI runs with elevated rights, the injected commands execute as root, giving the attacker full control of the management appliance — a local privilege escalation to the highest privilege level. Organizations running affected GMS builds — typically enterprises and managed service providers that use GMS Virtual Appliances to centrally manage SonicWall firewalls — are affected. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 1.2%, so exploitation is not currently known to be occurring.

Do: Upgrade GMS Virtual Appliances to a fixed release per SonicWall's advisory — any build newer than 9.5.1 (Build 9510.1044) — and verify the running build in the appliance interface. Until patched, restrict CLI and appliance login access to trusted administrators with least-privilege accounts, since exploitation requires authenticated low-privileged access. Monitor appliance logs for unexpected local command execution, and treat management appliances as high-value targets given the root-level access a successful exploit grants.

6.31%
  • SonicWall GMS Virtual Appliance — GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and all earlier versions
moderate≈ low tens of thousands of GMS Virtual Appliance deployments worldwide (estimate; no public install-base figure provided)
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66148.

This source does not provide full text. Read it at zerodayinitiative.com.