Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-83549

OS Command Injection in SonicWall SMA1000 AMC

Post-auth OS command injection in the SonicWall SMA1000 AMC allows an authenticated administrator to execute arbitrary OS commands. CVSS 7.8 HIGH. Chains with CVE-2026-83548 for unauthenticated RCE.

cat cve-2026-83549.json
Vendor
SonicWall
Product
SMA1000 Appliance Management Console
CVSS
7.8
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

CVE-2026-83549 is an OS command injection flaw in the SonicWall SMA1000 Appliance Management Console (AMC). Classified as an Improper Neutralization of Special Elements used in an OS Command vulnerability. Under specific conditions, an authenticated attacker with administrator-level access can execute arbitrary OS commands remotely.

CVSS 7.8 (HIGH), per NVD. Published September 1, 2026.

In isolation, exploitation requires administrator credentials. Chained with CVE-2026-83548, a pre-authentication SSRF in the SMA1000 Workplace interface, unauthenticated attackers can bypass that requirement and reach remote code execution.

Both vulnerabilities are confirmed under active exploitation as of the September 1, 2026 SonicWall disclosure. Consult the SonicWall PSIRT advisory for affected firmware versions and patches.