nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-66149 CVE-2026-66149
HIGH
SonicWall Email Security OS Command Injection via Netmask in Restricted CLI
Record summary
CVE-2026-66149 has a selected CVSS score of 7.8 (high).
Description
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Email SecurityBrowse SonicWall / Email SecurityDefault status: unknown | CVE List | 10.0.35.8405 and earlier versions | affected |
References
2psirt.global.sonicwall.comVendor advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0012