Published on August 26, 2026

[CVE-2026-66152, CVE-2026-66153] SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root


Severity

High

Detail

SonicWall has disclosed two security vulnerabilities affecting the NetExtender Linux Client under advisory SNWLID-2026-0013. The most severe vulnerability, CVE-2026-66152 is a path traversal flaw in the handling of OPSWAT tarball files that could allow an attacker to write arbitrary files with root privileges on affected Linux systems. Successful exploitation could allow unauthorized creation or modification of files with root privileges, potentially leading to privilege escalation, system compromise, or disruption of affected systems.

The second vulnerability, CVE-2026-66153 (CVSS 7.0), is an improper link resolution vulnerability in the NetExtender NEService auto-upgrade process. A local low-privileged attacker could exploit symbolic links to manipulate file operations performed by the privileged service, potentially resulting in unauthorized modification of files accessible by the service.

At the time of disclosure, SonicWall indicated that there was no evidence that either vulnerability had been exploited in the wild. SonicWall recommends upgrading to NetExtender Linux Client version 10.3.6 or later, as no workaround is available.

CVE IDSummaryCVSS Score
CVE-2026-66152A path traversal vulnerability in the SonicWall NetExtender Linux Client could allow an attacker to write arbitrary files with root privileges.8.8 (High)  
CVE-2026-66153An improper link resolution vulnerability in the NetExtender Linux Client auto-upgrade process could allow a local low-privileged attacker to manipulate privileged file operations through symbolic link abuse.7.0 (Medium)

Affected Products

The vulnerabilities affect SonicWall NetExtender Linux Client versions 10.3.5 and earlier. The fixed release is NetExtender Linux Client version 10.3.6 and later.

SonicWall confirmed that Windows-based NetExtender client versions are not affected by these vulnerabilities.

Recommendation

Organizations should implement the following measures to reduce the risk of exploitation:

  • Upgrade NetExtender Linux Client to version 10.3.6 or later to address both vulnerabilities.
  • Identify all Linux systems running version 10.3.5 or earlier and prioritize them for immediate patching.
  • Review unmanaged Linux endpoints to ensure vulnerable NetExtender installations are not overlooked.
  • Monitor systems for unexpected file modifications, suspicious symbolic links, or unauthorized changes to privileged files.
  • Verify patch deployment through vulnerability scanning and endpoint management tools to ensure all affected systems have been upgraded.

Source

https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0013