{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-66145", "assignerOrgId": "44b2ff79-1416-4492-88bb-ed0da00c7315", "state": "PUBLISHED", "assignerShortName": "sonicwall", "dateReserved": "2026-07-24T08:34:11.798Z", "datePublished": "2026-08-11T20:05:18.939Z", "dateUpdated": "2026-08-12T14:46:28.752Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "44b2ff79-1416-4492-88bb-ed0da00c7315", "shortName": "sonicwall", "dateUpdated": "2026-08-11T20:05:18.939Z" }, "datePublic": "2026-08-11T20:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-94", "description": "CWE-94 Improper Control of Generation of Code ('Code Injection')", "type": "CWE" } ] } ], "affected": [ { "vendor": "SonicWall", "product": "GMS", "platforms": [ "Windows", "Linux" ], "versions": [ { "status": "affected", "version": "9.5.1 and earlier versions" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip." } ] } ], "references": [ { "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011", "tags": [ "vendor-advisory" ] } ], "source": { "advisory": "SNWLID-2026-0011", "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.4" } }, "adp": [ { "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 9.1, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-12T04:00:44.874926Z", "id": "CVE-2026-66145", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-12T14:46:28.752Z" } } ] } }