CVE-2026-78327 PUBLISHED

Assigner: sonicwall
Reserved: 24.08.2026 Published: 04.09.2026 Updated: 04.09.2026

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

Product Status

Vendor SonicWall
Product Network Security Manager (NSM)
Versions Default: unknown
  • Version 4.3.0 and earlier versions is affected

Credits

  • Andrei Lungu and Matei "Mal" Badanoiu of Pentest-Tools.com reporter

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE