CVE-2026-102255

SonicWall SMA1000

Published 7 Oct 2026 · updated 7 Oct 2026 · Awaiting Analysis

10.0 Critical · CVSS 3.1, CISA ADP

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

References