ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability
ZDI advisory discloses SonicWall Email Security snmp command injection local privilege escalation (CVE-2026-66150, CVSS 7.8).
ZDI advisory ZDI-26-530 describes a command injection vulnerability in the snmp component of SonicWall Email Security, tracked as CVE-2026-66150 with a CVSS score of 7.8. Local attackers who can already execute low-privileged code on the target can escalate privileges on affected installations.
- Command injection via snmp in SonicWall Email Security
- CVE-2026-66150, CVSS 7.8, local privilege escalation
- Requires existing low-privileged code execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66150 | Authenticated CLI command injection to root in SonicWall Email Security via SNMP CVE-2026-66150 is a code injection flaw (CWE-94) in the SonicWall Email Security appliance in which the restricted CLI improperly controls command generation for SNMP-related functions. An attacker who has already authenticated to the restricted CLI with low-level privileges can inject arbitrary operating system commands through the SNMP pathway, and those commands execute with root privileges. Successful exploitation therefore yields full compromise of the appliance — read, write, and availability impact as root — making it effectively a local privilege escalation from a restricted administrative account to total system control. Any organization running an on-premises SonicWall Email Security appliance is potentially exposed, though exploitation requires the attacker to first obtain authenticated CLI access, such as via a compromised or misused admin account. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days. Do: Track the SonicWall PSIRT advisory (CVE-2026-66150) and apply the patched firmware as soon as a fixed version is published. In the interim, limit restricted CLI access to trusted administrators, audit which accounts have CLI access for signs of compromise, and disable or restrict the SNMP service on the appliance if it is not required. Because exploitation requires prior authenticated CLI access, prioritize remediation on appliances where admin credentials may have been shared or exposed. | 7.8 | <1% |
| moderatelikely on the order of tens of thousands of appliance deployments (roughly 10k–100k); no public install-base figure is available |
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66150.
This source does not provide full text. Read it at zerodayinitiative.com.