CVE-2026-66149: Code Injection
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the SonicWall Email Security restricted CLI to only trusted administrative hosts/users to prevent authenticated code injection via the restricted CLI.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66149?
The severity of CVE-2026-66149 is rated at 60.
How do I fix CVE-2026-66149?
To fix CVE-2026-66149, upgrade your SonicWall Email Security appliance to the latest patched version provided by SonicWall.
Who is affected by CVE-2026-66149?
CVE-2026-66149 affects authenticated users with access to the restricted CLI of SonicWall Email Security appliances.
What type of vulnerability is CVE-2026-66149?
CVE-2026-66149 is classified as a Code Injection vulnerability.
What can an attacker do with CVE-2026-66149?
An attacker can inject arbitrary OS commands that execute as root, compromising the affected SonicWall Email Security appliance.