Ten Out of Ten at the Login Portal: SonicWall's CVE-2026-102255 Pre-Auth SSRF in SMA1000

On 6 October 2026, SonicWall published security advisory SNWLID-2026-0017 covering four vulnerabilities in the Secure Mobile Access 1000 series — the appliances that sit at the edge and authenticate every remote user. The lead item, CVE-2026-102255, is a pre-authentication server-side request forgery in the WorkPlace login portal, reachable through what SonicWall calls an unintended alternate access path, scored CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C). An unauthenticated remote attacker can direct the appliance to issue requests on their behalf, reaching internal functions and performing unauthorised operations. The portal everyone must touch is the attack surface.

NVD published all four CVE records on 7 October 2026. The set, as recorded:

  • CVE-2026-102255 — 10.0 Critical. Pre-auth SSRF in the WorkPlace interface. Scope-changed (S:C), no privileges, no user interaction. This is the patch-now item.
  • CVE-2026-102256 — 7.8 High (CWE-78). Post-authentication OS command injection: a remote authenticated attacker as administrator can execute arbitrary OS commands, resulting in RCE. Researcher credit to Brian Mariani.
  • CVE-2026-102257 — 7.2 High (CWE-22). A Zip Slip path traversal in the Appliance Management Console: a crafted archive extracts files outside the intended directory, resulting in RCE. Also credited to Mariani.
  • CVE-2026-102258 — 6.1 Medium (CWE-79). Post-authentication stored XSS in the AMC, allowing an administrator-context attacker to store and execute arbitrary JavaScript in the management console.

Note the shape of the three siblings: each requires administrator authentication, which caps the CVSS but should not cap your concern. An SSRF that reaches internal functions (102255) chained with an admin-context RCE (102256 or 102257) is the textbook escalation path on exactly this class of device — and VPN/remote-access appliances are where stolen admin session tokens go to become domain-wide incidents. SonicWall states it currently has no evidence of exploitation in the wild for any of the four.

Scope and fixed builds

Affected: physical and virtual SMA 1000 models 6210, 7210, and 8200v. Fixed in hotfix firmware 12.4.3-03670 and higher and 12.5.0-03082 and higher — SonicWall strongly advises upgrading to those releases. Explicitly not affected: SonicWall's firewall products and the discontinued, unsupported SMA 100 series. If your asset inventory lumps “SonicWall SSL VPN” into one line, this advisory is the reason to split it: the 100 series being out of scope and the 1000 series being at maximum severity is a distinction that matters at 2 a.m.

Context from a week that keeps hitting the edge: this lands days after the NetScaler SAML bulletin that sent admins back for a second upgrade in eight days. Remote-access infrastructure is having a rough October, and the pattern is consistent — unauthenticated-reachable flaws in the exact components (login portals, SAML handlers) that cannot be taken offline without cutting off the workforce.

What to do

  • Patch the WorkPlace-facing appliances first. Target hotfixes 12.4.3-03670+ or 12.5.0-03082+, prioritising internet-facing 6210/7210/8200v units. The 10.0 is pre-auth on the login portal — there is no compensating credential control for “no credentials required.”
  • Restrict WorkPlace and AMC exposure while the change window is scheduled. Limit source addresses for the portal and management console to what the remote workforce and admin team actually need. SSRF through an alternate access path is harder to WAF away than a single malicious parameter, but shrinking the reachable surface still cuts opportunistic scanning.
  • Hunt for SSRF-shaped egress, not just exploitation artefacts. Review appliance outbound request logs for unexpected internal destinations or connections to external hosts originating from the appliance itself. SonicWall reports no known exploitation — verify that statement against your own logs rather than inheriting it.
  • Treat the admin-context siblings as escalation rungs. After patching, audit AMC administrator accounts and sessions: the 7.8 command injection and 7.2 Zip Slip only need an authenticated administrator, and a 10.0 SSRF is precisely the kind of primitive that helps an attacker become one.
  • Fix the inventory line. Confirm each appliance's model and firmware branch (12.4.x vs 12.5.x map to different hotfixes), and separate SMA 1000 from firewall and SMA 100 entries so the next advisory routes to the right owner immediately.

Verification note: we read the NVD API records for CVE-2026-102255 (CVSS 3.1 10.0, pre-auth SSRF via unintended alternate access path), CVE-2026-102256 (7.8, CWE-78 post-auth admin OS command injection), CVE-2026-102257 (7.2, CWE-22 Zip Slip in AMC), and CVE-2026-102258 (6.1, CWE-79 post-auth stored XSS in AMC) — all published 7 October 2026, all referencing SNWLID-2026-0017 — and the Help Net Security report for the advisory date (6 October 2026), affected models (6210, 7210, 8200v, physical and virtual), fixed hotfix versions (12.4.3-03670+ and 12.5.0-03082+), the firewall/SMA-100-series exclusions, the Mariani researcher credits, and the no-known-exploitation statement. The SonicWall PSIRT page itself renders client-side and could not be read directly; advisory contents are via NVD's CVE descriptions and the secondary report, attributed as such. We did not test any appliance and did not attempt exploitation.

Sources: