Back to vendor advisories
SonicWall PSIRT AdvisoriesSNWLID-2026-0011

SonicWall GMS Security Affected By Multiple Vulnerabilities

SonicWall GMS (Virtual Appliance, Windows) - 9.5.1 and earlier versions are vulnerable to the following security issues. 1) CVE-2026-66145 - An unauthenticated remote code execution vulnerability An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip. CVSS Score: 9.1 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CWE-94: Improper Control of Generation of Code ('Code Injection') 2) CVE-2026-66146 - GMS Multiple Cross-Site Scripting (XSS) Vulnerabilities Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser. CVSS Score: 5.5 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 3) CVE-2026-66147 - GMS Unauthenticated Command Injection in Dispatcher Service An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. CVSS Score: 9.4 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H CWE-94: Improper Control of Generation of Code ('Code Injection') 4) CVE-2026-66148 - GMS Local Privilege Escalation via Authenticated Command Injection An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. CVSS Score: 6.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE-94: Improper Control of Generation of Code ('Code Injection') 5) CVE-2026-66154 - GMS Weak Certificate Verification to User Compromise via MiTM An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes. CVSS Score: 8.3 CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-295: Improper Certificate Validation 6) CVE-2026-18634 - GMS Local

9.4CVSS out of 10Critical severity
Scope

What the vendor says is affected

  • GMS - Virtual Appliance and Windows: 9.5.1 and earlier versions

Versions the vendor lists as fixed

  • GMS - Virtual Appliance and Windows: 9.5.2
Next step

What the vendor recommends

Install the applicable fixed SonicWall release for your product and branch. GMS - Virtual Appliance and Windows: 9.5.2

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by SonicWall

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory