CVE-2026-66149

CVE-2026-66149CVE-2026-66149

Description

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

Scoring

CVSS 7.8 ()
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Last modified2026-08-11
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.