ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66148.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-531?
The severity of ZDI-26-531 is rated as 7, indicating a high level of risk.
What type of vulnerability is ZDI-26-531?
ZDI-26-531 is a command injection vulnerability that may lead to local privilege escalation.
How do I fix ZDI-26-531?
To fix ZDI-26-531, ensure that your SonicWall GMS Virtual Appliance is updated to the latest patched version addressing this vulnerability.
Who is affected by ZDI-26-531?
ZDI-26-531 affects installations of SonicWall GMS Virtual Appliance where local access to execute code is possible.
What conditions need to be met to exploit ZDI-26-531?
To exploit ZDI-26-531, an attacker must first gain the ability to execute low-privileged code on the target SonicWall GMS Virtual Appliance.