A pre-authentication vulnerability in the SonicWall SMA1000 series allows an unauthenticated request to turn the device into an unintended proxy for remote attackers. According to the SonicWall PSIRT advisory SNWLID-2026-0017, this mechanism, known as a confused deputy, permits the appliance to reach internal functionality and perform unauthorized operations without requiring any credentials.
The SMA1000 line has now drawn three disclosures with the same opening, a pre-authentication SSRF at the Work Place or proxy layer. This advisory lands four weeks after the second chain’s coverage asked whether the patches were treating symptoms instead of the root cause. Each cycle: an edge interface acting on a request without authentication, then execution-class bugs riding the appliance’s own privileges.
The first episode, detailed in the first chain’s origin story, involved CVE-2026-15409, a CVSS 10.0 pre-auth SSRF in /wsproxy, plus CVE-2026-15410 path traversal to root. It ended with TOTP MFA seed theft and ransomware activity attributed to UTA0533 and INC. The second episode, the second zero-day chain, involved SNWLID-2026-0016, CVE-2026-83548 (pre-auth SSRF in the Appliance Work Place interface) and CVE-2026-83549 (post-auth command injection in AMC). That piece closed on whether the patches were treating symptoms instead of the root cause.
The Current Vulnerability Bundle
The latest advisory covers four distinct vulnerabilities affecting SMA1000 models 6210, 7210, and 8200v. These bugs range from pre-authentication access to post-authentication execution.
- CVE-2026-102255: A pre-authentication SSRF in the Work Place interface. It carries a CVSS score of 10.0 (vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and is classified under CWE-918 and CWE-441. SonicWall notes it exists due to an unintended alternate access path. “By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” It was discovered by Benoît Sevens of Anthropic.
- CVE-2026-102256: A post-authentication OS command injection vulnerability. It carries a CVSS score of 7.8 and is classified under CWE-78. This allows an authenticated administrator to execute arbitrary OS commands. It was also discovered by Benoît Sevens of Anthropic.
- CVE-2026-102257: A post-authentication Zip Slip vulnerability in the Appliance Management Console. It carries a CVSS score of 7.2 and is classified under CWE-22. This allows file extraction outside the intended directory, leading to remote code execution. It was discovered by Brian Mariani through ZDI (Zero Day Initiative) Trend Micro, ZDI-CAN-28924.
- CVE-2026-102258: A post-authentication stored cross-site scripting vulnerability in the Appliance Management Console. It carries a CVSS score of 5.5 and is classified under CWE-79. It was discovered by Brian Mariani of DigitalCanion SA.
Architectural Recurrence
This does not prove the three chains share root-cause code. It establishes a recurring shape on one product line. The consistent appearance of an unauthenticated SSRF door at the edge interface suggests that the trust boundary is fundamentally misaligned with the product’s operational requirements.
When the same type of vulnerability appears repeatedly across three disclosure cycles, the fix is design, not the patch list. The appliance is consistently acting on behalf of requests before any credential verification occurs. This creates a persistent path for attackers to reach the more sensitive execution-class bugs located behind the edge.
Defender Guidance
SonicWall has provided specific firmware updates to address these vulnerabilities. Users must upgrade from 12.4.3-03526 (platform-hotfix) and older to 12.4.3-03670 (platform-hotfix) and higher, or from 12.5.0-02952 (platform-hotfix) and older to 12.5.0-03082 (platform-hotfix) and higher. Workaround: None. “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.” The SSL-VPN functionality on SonicWall firewalls and the SMA 100 Series are not affected.
Recent disclosures involving Cisco FMC (two CVSS 10.0 unauthenticated RCEs), Cisco NX-OS (six unauthenticated RCEs across four functional planes), and the Splunk Enterprise Patroni REST API (unauthenticated OS command execution) show similar risks across diverse product architectures.
Three cycles of the same door is a design record, not a coincidence of bug reports. The firmware closes this bundle; the next one closes when the trust boundary stops acting on unauthenticated requests.
