Junglewise Threat Intelligence

CVE-2026-66145: SonicWall GMS remote code execution via zipslip

CVE-2026-66145 · Severity: critical · CVSS 9.1 · Published 2026-08-11

Vendors: SonicWall.

Executive brief

GMS (Gesture Management System) is SonicWall's centralized management platform for security appliances. An unauthenticated remote attacker can exploit a path traversal vulnerability in archive handling to write arbitrary files and execute code on the management server, compromising all connected security devices and sensitive organizational data.

Technical details

The vulnerability is a zipslip path traversal flaw in archive extraction logic that allows unauthenticated remote attackers to read sensitive data and perform arbitrary file writes on the GMS server. The vulnerability exists in GMS versions 9.5.1 (Build 9510.1044) and earlier. Because GMS is a centralized management console typically accessible from the network, the attack vector is network-based and requires no authentication or user interaction. An attacker can leverage arbitrary file write to achieve remote code execution with GMS process privileges.

Affected products

  • SonicWall GMS 9.5.1 (Build 9510.1044) and earlier

Timeline

  • 2026-08-11: disclosed

References

Related threats