SonicWallCVE-2026-66147
SonicWall GMS: command injection
Critical9.4CVE-2026-66147 · Published Aug 11, 2026 · updated Aug 28, 2026
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GMS Product | <= 9.5.1 and earlier versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-94
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SonicWall GMS: command injection | Medium6.3 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall GMS: improper certificate validation | High8.3 | No fix yet |
| Aug 11 | SonicWall GMS: unsafe deserialization | High8.4 | No fix yet |
| Aug 11 | SonicWall GMS: remote code execution | Critical9.1 | No fix yet |