CVE-2026-81939 PUBLISHED

Assigner: sonicwall
Reserved: 27.08.2026 Published: 04.09.2026 Updated: 04.09.2026

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

Product Status

Vendor SonicWall
Product Network Security Manager (NSM)
Versions Default: unknown
  • Version 4.3.0 and earlier versions is affected

Credits

  • Andrei Lungu of Pentest-Tools.com finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE