CVE-2026-66145 PUBLISHED

Assigner: sonicwall
Reserved: 24.07.2026 Published: 11.08.2026 Updated: 12.08.2026

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

Product Status

Vendor SonicWall
Product GMS
Versions Default: unknown
  • Version 9.5.1 and earlier versions is affected

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE