Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
History

Thu, 09 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-04-09T14:22:21.018Z

Reserved: 2026-03-13T11:57:18.440Z

Link: CVE-2026-4112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-09T15:16:13.517

Modified: 2026-04-09T15:16:13.517

Link: CVE-2026-4112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.