nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-66150 CVE-2026-66150
HIGH
SonicWall Email Security Restricted CLI OS Command Injection via SNMP
Record summary
CVE-2026-66150 has a selected CVSS score of 7.8 (high).
Description
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Email SecurityBrowse SonicWall / Email SecurityDefault status: unknown | CVE List | 10.0.35.8405 and earlier versions | affected |
References
2psirt.global.sonicwall.comVendor advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0012