CVE-2026-66154

HIGH CVSS 3.1: 8.3 EPSS 0.13%
Updated Aug 12, 2026
Sonicwall
Parameter Value
CVSS 8.3 (HIGH)
Type CWE-295 (Improper Certificate Validation)
Vendor Sonicwall
Public PoC No

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

sonicwall:gms