CVE-2026-102255
SonicWall SMA1000
Published 7 Oct 2026 · updated 7 Oct 2026 · Awaiting Analysis
10.0 Critical · CVSS 3.1, CISA ADP
Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.