AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66149

HIGH · CVSS 7.8 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The SonicWall Email Security appliance is vulnerable to a code injection flaw that allows authenticated attackers with access to the restricted command-line interface (CLI) to execute arbitrary OS commands with root privileges. This could lead to unauthorized access, data manipulation, or system compromise. Organizations using this appliance should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-66149
Severity
HIGH
CVSS
7.8
EPSS
0.20%

Original NVD Description

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.