CVE-2026-66150 PUBLISHED

Assigner: sonicwall
Reserved: 24.07.2026 Published: 11.08.2026 Updated: 12.08.2026

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.

Product Status

Vendor SonicWall
Product Email Security
Versions Default: unknown
  • Version 10.0.35.8405 and earlier versions is affected

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE