Junglewise Threat Intelligence

CVE-2026-8480: Stormshield Network Security improper certificate validation in admin portal

CVE-2026-8480 · Severity: medium · CVSS 4.3 · Published 2026-07-01

Technologies: Stormshield Network Security. Vendors: Stormshield.

Executive brief

Stormshield Network Security firewalls contain a flaw where revoked security certificates are not properly invalidated for administrative access. This means a former employee or an unauthorized individual possessing a revoked certificate could still log into the management portal. An attacker with this access could potentially view sensitive configuration data or manage the security appliance.

Technical details

An improper certificate validation vulnerability (CWE-295) exists in the captive-admin portal of Stormshield Network Security (SNS). The system fails to check the revocation status of client certificates in real-time, allowing a revoked certificate to remain valid for authentication. The attack vector is restricted to the adjacent network. Attackers possessing a revoked but otherwise valid certificate can gain administrative access to the portal. The issue is resolved in versions 5.0.6, 4.8.16, and 4.3.42; a manual workaround involves restarting the 'sld' service after certificate revocation.

Affected products

  • Stormshield Stormshield Network Security 4.3.0 to 4.3.41, 4.4.0 to 4.8.15, 5.0.2 EA to 5.0.5

Timeline

  • 2025-05-11: disclosed: Date discovered
  • 2026-02-19: advisory: Initial advisory release
  • 2026-07-01: advisory: NVD publication date

References

Related threats