CVE-2026-66150: Code Injection
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-66150?
CVE-2026-66150 is a code injection vulnerability in SonicWall Email Security that allows authenticated attackers to inject and execute arbitrary OS commands as root.
What is the severity of CVE-2026-66150?
CVE-2026-66150 has a risk score of 55, indicating a moderate severity level.
How do I fix CVE-2026-66150?
To address CVE-2026-66150, update your SonicWall Email Security appliance to the latest version that includes the security patches.
Who is affected by CVE-2026-66150?
Only authenticated users with access to the restricted CLI of the SonicWall Email Security appliance are affected by CVE-2026-66150.
What are the potential impacts of CVE-2026-66150?
CVE-2026-66150 can allow attackers to execute arbitrary commands on the server, potentially leading to unauthorized access and data breaches.