An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonicwall
Sonicwall network Security Manager |
|
| Vendors & Products |
Sonicwall
Sonicwall network Security Manager |
Sat, 05 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection Allowing Remote Code Execution in SonicWall Network Security Manager On‑Prem Management Interface |
Sat, 05 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection via SuperAdmin Privileges in SonicWall Network Security Manager |
Fri, 04 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection via SuperAdmin Privileges in SonicWall Network Security Manager | |
| Metrics |
cvssV3_1
|
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution. | |
| Weaknesses | CWE-78 | |
| References |
|
Status: PUBLISHED
Assigner: sonicwall
Published: 2026-09-04T18:14:54.641Z
Updated: 2026-09-04T19:50:05.348Z
Reserved: 2026-08-24T09:38:44.377Z
Link: CVE-2026-78327
Updated: 2026-09-04T19:49:59.827Z
Status : Awaiting Analysis
Published: 2026-09-04T19:17:27.347
Modified: 2026-09-08T19:12:59.557
Link: CVE-2026-78327
No data.