What is CVE-2026-66149?
CVE-2026-66149 is a code injection vulnerability in the SonicWall Email Security appliance that allows an authenticated attacker with restricted CLI access to execute arbitrary OS commands as root via the netmask parameter. This could lead to full device compromise, and applying the vendor-supplied security patch is critical.
Azərbaycanca: Bu CVE-2026-66149, SonicWall Email Security cihazında autentifikasiya olunmuş hücumçunun məhdud CLI interfeysi vasitəsilə 'netmask' parametrindən istifadə edərək root səviyyəsində ixtiyari OS əmrlərini icra edə biləcəyi kod inyeksiyası zəifliyidir. Bu, cihazın tam ələ keçirilməsinə səbəb ola bilər, ona görə SonicWall tərəfindən təqdim olunan təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: SonicWall
FAQ2
What level of access does an attacker need to exploit CVE-2026-66149?
The attacker must have authenticated access to the restricted CLI interface on the SonicWall Email Security appliance.
At what privilege level are commands executed when CVE-2026-66149 is exploited?
Arbitrary OS commands can be executed as root.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.