nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-66147 CVE-2026-66147
CRITICAL
SonicWall GMS Dispatcher Service Command Injection
Record summary
CVE-2026-66147 has a selected CVSS score of 9.4 (critical).
Description
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 9.5.1 and earlier versions | affected |
References
2psirt.global.sonicwall.comVendor advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011