CVE-2026-102258
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).
| CWE | CWE-79 |
| Vendor | sonicwall |
| Product | sma1000 |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonicwall sma1000
Be the first to know when new medium vulnerabilities affecting sonicwall sma1000 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SonicWall / SMA1000
12.4.3-03526 (platform-hotfix) and older versions 12.5.0-02952 (platform-hotfix) and older versions
References
Credits
Brian Mariani