CVE-2026-102258

SMA: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-102258)

mediumEPSS 0.4%

Description

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

SonicWallSMA
1000 Models 6210 <12.4.3-036701000 Models 6210 <12.5.0-030821000 Models 7210 <12.4.3-036701000 Models 7210 <12.5.0-030821000 Models 8200v <12.4.3-036701000 Models 8200v <12.5.0-03082

Metrics

6.1
Source: cna-v3
31.3 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-07 14:17 UTC
CWE-79

Weakness classes (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-07 15:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    • SSVC: {"id":"CVE-2026-102258","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  2. New CVE Received2026-10-07 14:17 UTC· PSIRT@sonicwall.com
    • Description: Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).
    • CWE: CWE-79
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/102xxx/CVE-2026-102258.json">CVE-2026-102258</a>
    • Reference: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017

Linked advisories