Published on October 7, 2026
[CVE-2026-102255] SonicWall SMA1000 SSRF Vulnerability Could Allow Unauthorized Access to Internal Functionality
Severity
Critical
Detail
SonicWall has released hotfixes to address a critical Server-Side Request Forgery (SSRF) vulnerability affecting SMA1000 Series secure access appliances. The vulnerability, tracked as CVE-2026-102255, affects the Appliance WorkPlace interface of SMA1000 appliances.
The vulnerability stems from an unintended alternate access path that could allow a remote, unauthenticated attacker to abuse the appliance as a proxy and access internal functionality. Successful exploitation may enable unauthorized operations against the affected device without requiring valid credentials.
According to SonicWall, the vulnerability affects SMA1000 6210, 7210, and 8200v appliances. The company confirmed that SMA 100 Series appliances and SSL-VPN services running on SonicWall firewalls are not affected.
Although SonicWall has not observed active exploitation in the wild, the company strongly recommends that customers deploy the released hotfixes immediately due to the severity of the vulnerability and the high value of SMA1000 appliances as targets for threat actors.
| CVE ID | Summary | CVSS Score |
| CVE-2026-102255 | A SSRF vulnerability in the Appliance WorkPlace interface that could allow a remote unauthenticated attacker to access internal functionality and perform unauthorized operations. | 10.0 (Critical) |
| CVE-2026-102256 | Post-authentication OS command injection vulnerability that could allow command execution on the affected appliance. | 7.8 (High) |
| CVE-2026-102257 | Path traversal vulnerability in the Appliance Management Console. | 7.2 (High) |
| CVE-2026-102258 | Cross-site scripting (XSS) vulnerability in the Appliance Management Console. | 5.5 (Medium) |
Affected Products
The vulnerabilities affect SonicWall SMA1000 Series appliances, including the SMA1000 6210, 7210, and 8200v models running the following versions:
- 12.4.3-03526 and earlier
- 12.5.0-02952 and earlier
SonicWall confirmed that SMA 100 Series appliances and SSL-VPN services running on SonicWall firewalls are not affected.
Recommendation
Organizations should implement the following measures immediately:
- Upgrade affected SMA1000 appliances to the latest hotfix release provided by SonicWall.
- Identify all internet-facing SMA1000 appliances and prioritize remediation.
- Restrict access to management interfaces to trusted administrative networks.
- Monitor appliance logs for unusual requests and unauthorized administrative activity.
- Review historical access logs for indicators of suspicious exploitation attempts.
- Conduct security assessments of affected appliances, particularly those exposed directly to the internet.
Source
- https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
- https://www.helpnetsecurity.com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-102255/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
- https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0017/kA1VN000002QP3G0AW
