Junglewise Threat Intelligence

CVE-2026-78328: SonicWall Network Security Manager privilege escalation in management interface

CVE-2026-78328 · Severity: critical · CVSS 9.1 · Published 2026-09-04

Executive brief

SonicWall Network Security Manager (NSM) On-Prem is a centralized management platform used to administer firewall and network security policies across an organization. A missing authorization check allows a lower-privileged Admin user to escalate their account to SuperAdmin level, potentially gaining full control over all managed security devices and configurations.

Technical details

This vulnerability is a missing authorization (authorization bypass) flaw in the NSM On-Prem management interface. A lower-privileged Admin user can escalate privileges to SuperAdmin through an unauthenticated or insufficiently authorized API or management operation. The vulnerability is network-reachable and requires an existing Admin account; no additional user interaction is needed. A successful exploitation grants an attacker full administrative control over the NSM platform and all connected security infrastructure. Patches are expected from SonicWall; check PSIRT advisory SNWLID-2026-0015 for available updates.

Affected products

  • SonicWall Network Security Manager (NSM) On-Prem <UNKNOWN>

Timeline

  • 2026-09-04: disclosed

References