Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-102255: SonicWall SMA1000 can be tricked into internal requests
CVE-2026-102255 · published 3 days ago
Summary
The SMA1000 appliance’s Workplace interface allows outsiders to send the device its own network requests without logging in. This could let an attacker reach hidden internal functions and carry out actions they shouldn’t. Apply the vendor’s latest update or restrict external access to the interface to mitigate the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| sonicwall | sma1000 | 12.4.3-03526 (platform-hotfix) and older versions |
Original advisory text
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker coul...
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Severity
10.0
Critical
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta