Junglewise Threat Intelligence

CVE-2026-8482: Stormshield Network Security information leak in CLI history

CVE-2026-8482 · Severity: medium · CVSS 4.3 · Published 2026-07-02

Technologies: Stormshield Network Security. Vendors: Stormshield.

Executive brief

A security vulnerability has been identified in Stormshield Network Security firewalls that could allow sensitive administrative credentials to be exposed. If multiple administrators have access to the device's command-line interface, one user may be able to view secret information entered by another, such as encryption passphrases or hardware security passwords. This could lead to an unauthorized person gaining deeper access to the network's security infrastructure.

Technical details

An information leak vulnerability (CWE-532) exists in the NSRPC client history of Stormshield Network Security (SNS). When administrators use the CLI command-line tool to execute commands, sensitive information such as the proxy CA passphrase or TPM password may be recorded in a way that is accessible to other users with SSH access to the firewall (specifically when SSH multiuser mode is enabled). The attack vector is classified as 'Adjacent' with high privileges required and user interaction. The vulnerability is addressed in versions 4.3.42, 4.8.16, and 5.0.6.

Affected products

  • Stormshield Stormshield Network Security 4.3.0 to 4.3.41, 4.8.0 to 4.8.15, 5.0.0 to 5.0.5

Timeline

  • 2025-05-26: disclosed: Vulnerability discovered
  • 2025-12-29: advisory: Initial advisory release (v1)
  • 2026-07-02: advisory: NVD publication date

References