ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
ZDI discloses CVE-2026-66148, a command injection local privilege escalation in SonicWall GMS Virtual Appliance rated CVSS 7.8.
ZDI-26-531 describes a command injection vulnerability in the SonicWall GMS Virtual Appliance interface that allows local attackers to escalate privileges. Exploitation requires the attacker to first execute low-privileged code on the target system. ZDI assigned a CVSS score of 7.8, tracked as CVE-2026-66148.
35