CVE-2026-66147 PUBLISHED

Assigner: sonicwall
Reserved: 24.07.2026 Published: 11.08.2026 Updated: 12.08.2026

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

Product Status

Vendor SonicWall
Product GMS
Versions Default: unknown
  • Version 9.5.1 and earlier versions is affected

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE