CVE-2026-4112
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series app
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
HIGH · CVSS 7.2
EPSS 0.00033
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0