Junglewise Threat Intelligence

CVE-2026-3468: SonicWall Email Security stored XSS

CVE-2026-3468 · Severity: medium · CVSS 4.8 · Published 2026-03-31

Technologies: SonicWall Esa9000, SonicWall Esa7050, SonicWall Esa7000, SonicWall Esa5000, SonicWall Esa5050, SonicWall Email Security. Vendors: SonicWall.

Executive brief

SonicWall Email Security is a solution used to protect corporate email from threats like spam and malware. A security flaw has been found that allows an authenticated administrator to inject malicious scripts into the management interface. If another user views the affected page, the script could execute in their browser, potentially leading to unauthorized actions or data access within the management console.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is reachable over the network but requires high privileges, specifically an authenticated administrator account. An attacker can inject malicious JavaScript into the application's database, which is then executed in the context of another user's session when they navigate to the affected page. This could lead to session hijacking or unauthorized configuration changes. The issue affects versions 10.0.34.8215, 10.0.34.8223, and earlier; users should update to version 10.0.35.8405 or later.

Affected products

  • SonicWall Email Security 10.0.34.8215 and earlier; 10.0.34.8223 and earlier

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: advisory

References

Related threats