CVE-2026-102257: Path Traversal
Published Oct 7, 2026
·Updated
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
Affected Software
1 affected component
SonicWall SMA1000 Appliance Management Console (AMC)
Event History
Oct 7, 2026
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can this be exploited without authentication?
No. The CVSS vector indicates high privileges are required, so an attacker must already have high-level access to the AMC interface.
2
Is network access sufficient for exploitation?
No. Although the attack vector is network-based and requires no user interaction, the attacker also needs high privileges and a specially crafted archive.