Junglewise Threat Intelligence

CVE-2026-3469: SonicWall Email Security denial of service via improper input validation

CVE-2026-3469 · Severity: low · CVSS 2.7 · Published 2026-03-31

Technologies: SonicWall Esa9000, SonicWall Esa7050, SonicWall Esa7000, SonicWall Esa5000, SonicWall Esa5050, SonicWall Email Security. Vendors: SonicWall.

Executive brief

A security flaw in the SonicWall Email Security appliance could allow an authorized administrator to inadvertently or intentionally crash the system. This appliance is used to protect corporate email from threats like spam and phishing. If exploited, the email security service would become unresponsive, potentially disrupting email flow or management capabilities.

Technical details

An improper input validation vulnerability (CWE-20) exists in the SonicWall Email Security appliance. A remote attacker with high-level administrative privileges can provide specially crafted input that the system fails to process correctly, leading to a denial-of-service (DoS) condition where the application becomes unresponsive. The attack is carried out over the network but requires valid administrative credentials (PR:H). The vulnerability affects versions 10.0.34.8215, 10.0.34.8223, and earlier.

Affected products

  • SonicWall Email Security 10.0.34.8215 and earlier, 10.0.34.8223 and earlier

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: advisory: SonicWall PSIRT published SNWLID-2026-0002

References

Related threats