Overview
What is CVE-2026-102255?
CVE-2026-102255 is a pre-authentication server-side request forgery vulnerability in the SonicWall SMA1000 Appliance Work Place interface. An unauthenticated remote attacker can use an unintended access path to make the appliance send requests, reach internal functionality and perform unauthorized operations. SonicWall assigns a CVSS 3.0 score of 10.0.
Source: SonicWall · Reviewed Oct 7, 2026
- Affected deployments
SMA1000 models 6210, 7210 and 8200v running affected 12.4.3 or 12.5.0 platform hotfixes. SonicWall says SSL-VPN on its firewall products is not affected.
- Patch status
Fixed platform hotfixes are available for both branches. SonicWall lists no workaround.
- Vendor exploitation statement
In the October 6 bulletin, SonicWall says there is currently no evidence that any of the vulnerabilities addressed in this release are being exploited in the wild. This is a dated vendor statement, not proof that an installation is safe.
Original NVD description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Affected software
Products and fixed versions
SonicWall guidance
Applies to SMA1000 models 6210, 7210 and 8200v. Install the fixed platform hotfix for the running branch, or a later version recommended by SonicWall.
| Product / branch | Affected versions | Fixed build |
| SonicWall SMA100012.4.3 | 12.4.3-03526 (platform-hotfix) and older versions | 12.4.3-03670 (platform-hotfix) or higher |
| SonicWall SMA100012.5.0 | 12.5.0-02952 (platform-hotfix) and older versions | 12.5.0-03082 (platform-hotfix) or higher |
Use the listed fixed build or a later release in the same branch.