ZDI-26-531: SonicWall GMS Virtual Appliance Command Injection (CVE‑2026‑66148) Enables Local Privilege Escalation
What It Is — A command‑injection flaw in the SonicWall GMS Virtual Appliance interface allows an attacker who can run low‑privileged code to execute arbitrary commands as root.
Exploitability — Local‑only; requires prior foothold. No public exploit code, but the CVSS 7.8 rating (AV:L/AC:L/PR:L/UI:N) indicates a high likelihood of exploitation once an attacker has low‑privilege access.
Affected Products — SonicWall GMS Virtual Appliance (all versions prior to the 2026‑08‑11 patch).
Why It Matters for Compliance & Audit Readiness
- Control Mapping: The flaw highlights gaps in your privileged‑access controls; mapping this to SOC 2 CC6.1 (Logical Access) demonstrates due diligence.
- Continuous Evidence: Patch status and configuration baselines must be captured continuously to provide audit‑ready proof that the vulnerability is remediated.
- Third‑Party Assurance: Organizations that rely on SonicWall for network management need documented verification that the vendor’s remediation is in place, a key element of vendor‑risk evidence for SOC 2.
Recommended Actions
- Verify the presence of the patch referenced in SonicWall’s advisory (SNWLID‑2026‑0011) across all GMS appliances.
- Update your CMDB and configuration‑management tooling to record patch level as evidence for SOC 2 control CC6.1.
- Incorporate a scheduled scan for the CVE‑2026‑66148 indicator into your continuous compliance monitoring platform.
Source: Zero Day Initiative advisory