CVE-2026-102255 CVSS 10.0 SSRF in SonicWall SMA1000 WorkPlace
Pre-auth SSRF on SMA1000 models 6210, 7210 and 8200v

CVE-2026-102255 CVSS 10.0 SSRF in SonicWall SMA1000 WorkPlace

SonicWall has patched four flaws in SMA1000 remote-access appliances, led by CVE-2026-102255, a pre-authentication server-side request forgery rated CVSS 10.0. Advisory SNWLID-2026-0017 was published on 6 October 2026. SonicWall says it has no evidence these four are being exploited. There is no workaround.

What happened

The SSRF is in WorkPlace, the portal users log in through. An unintended access path lets a remote attacker with no login direct the appliance to issue requests on their behalf and reach internal functions. SonicWall has not named which functions.

Three companion bugs need a login. CVE-2026-102256 is an OS command injection (CVSS 7.8) that needs an administrator. CVE-2026-102257 is a Zip Slip path traversal in the Appliance Management Console (CVSS 7.2). CVE-2026-102258 is stored XSS in AMC (CVSS 5.5) and needs an administrator.

This is the third CVSS 10.0 pre-auth SSRF SonicWall has fixed in WorkPlace this year. The July pair and the 1 September pair were both reported as exploited. The September fix builds, 12.4.3-03526 and 12.5.0-02952, are themselves in the affected range for this advisory. An appliance left on those builds still needs the new hotfix.

Who is affected

  • SMA1000 models 6210, 7210 and 8200v on 12.4.3-03526 and older. Fixed in 12.4.3-03670 and higher.
  • Same models on 12.5.0-02952 and older. Fixed in 12.5.0-03082 and higher.
  • SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.

What to do now

Install 12.4.3-03670 or 12.5.0-03082 from MySonicWall and plan for the reboot. Do not treat the 1 September builds as current. If the appliance is internet-facing, restrict WorkPlace and the management console to known admin networks while you patch. SonicWall has not asked for a re-image on this set, unlike the exploited July and September bugs, but review admin accounts after the upgrade anyway.

Source: The Hacker News, SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances. Vendor advisory: SNWLID-2026-0017.

Advantest confirms PII stolen in February ransomware attack
Advantest ransomware personal data notification