Junglewise Threat Intelligence

CVE-2026-78327: SonicWall Network Security Manager OS command injection

CVE-2026-78327 · Severity: critical · CVSS 9.1 · Published 2026-09-04

Executive brief

SonicWall Network Security Manager (NSM) is a centralized management platform for enterprise network security appliances. An authenticated attacker with administrative privileges can inject arbitrary commands into the management interface, allowing them to execute code on the underlying server and potentially gain full control of the security infrastructure.

Technical details

An OS command injection vulnerability exists in the SonicWall NSM On-Prem management interface due to improper neutralization of special characters in OS commands. The vulnerability resides in the management interface processing logic and requires the attacker to be authenticated with SuperAdmin privileges to exploit it. An authenticated attacker can inject arbitrary shell commands that are executed with the privileges of the NSM process on the underlying host, achieving unauthenticated remote code execution. The vulnerability likely stems from unsafe command construction or shell metacharacter handling in the administrative API or management console.

Affected products

  • SonicWall Network Security Manager

Timeline

  • 2026-09-04: disclosed

References