CVE-2026-102258 PUBLISHED

Assigner: sonicwall
Reserved: 28.09.2026 Published: 07.10.2026 Updated: 07.10.2026

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).

Product Status

Vendor SonicWall
Product SMA1000
Versions Default: unknown
  • Version 12.4.3-03526 (platform-hotfix) and older versions is affected
  • Version 12.5.0-02952 (platform-hotfix) and older versions is affected

Credits

  • Brian Mariani finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE