Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Project Subscriptions

Vendors Products
Sonicwall Subscribe
Sma1000 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Post-Authentication Remote Code Execution in SonicWall SMA1000 Appliance Management Console via Code Injection

Fri, 17 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Code Injection Compromise on SonicWall SMA1000

Thu, 16 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Code Injection Compromise on SonicWall SMA1000

Wed, 15 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall sma1000
Vendors & Products Sonicwall
Sonicwall sma1000

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Weaknesses CWE-94
References
Metrics kev

{'dateAdded': '2026-07-14T00:00:00+00:00', 'dueDate': '2026-07-17T00:00:00+00:00'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-07-16T03:55:20.277Z

Reserved: 2026-07-10T14:12:17.270Z

Link: CVE-2026-15410

cve-icon Vulnrichment

Updated: 2026-07-14T20:10:45.329Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T22:00:05Z

Weaknesses