CVE-2026-4112

Publication date

2026-04-09 14:22:21

Family

sonicwall

State

PUBLISHED

Description

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.