{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-66147", "assignerOrgId": "44b2ff79-1416-4492-88bb-ed0da00c7315", "state": "PUBLISHED", "assignerShortName": "sonicwall", "dateReserved": "2026-07-24T08:34:11.798Z", "datePublished": "2026-08-11T20:08:56.193Z", "dateUpdated": "2026-08-12T14:46:43.933Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "44b2ff79-1416-4492-88bb-ed0da00c7315", "shortName": "sonicwall", "dateUpdated": "2026-08-11T20:08:56.193Z" }, "datePublic": "2026-08-11T20:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-94", "description": "CWE-94 Improper Control of Generation of Code ('Code Injection')", "type": "CWE" } ] } ], "affected": [ { "vendor": "SonicWall", "product": "GMS", "platforms": [ "Windows", "Linux" ], "versions": [ { "status": "affected", "version": "9.5.1 and earlier versions" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests." } ] } ], "references": [ { "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011", "tags": [ "vendor-advisory" ] } ], "source": { "advisory": "SNWLID-2026-0011", "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.4" } }, "adp": [ { "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 9.4, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "LOW" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-12T04:00:43.777245Z", "id": "CVE-2026-66147", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-12T14:46:43.933Z" } } ] } }