CVE-2026-81939: Path Traversal
Published Sep 4, 2026
·Updated
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
Affected Software
1 affected component
SonicWall SonicWall Network Security Manager (NSM)
Event History
Sep 4, 2026
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
DescriptionWeakness
Frequently Asked Questions
1
Which NSM deployments are identified as affected?
The affected product is SonicWall Network Security Manager (NSM) On-Prem. The provided information does not identify other deployment models as affected.
2
What does an attacker need to provide to trigger the issue?
An attacker needs to supply a specially crafted archive through the NSM file upload and archive processing functionality. The archive is designed to cause extraction outside the intended destination directory.