CVE-2026-102255

Published Oct 7, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-102255 is a pre-authentication server-side request forgery (SSRF) vulnerability affecting SonicWall Secure Mobile Access (SMA) 1000 series appliances, specifically models 6210, 7210, and 8200v. The flaw resides in the Appliance WorkPlace interface, which is the web portal users access to log in and reach internal applications. It stems from an unintended alternate access-path weakness that allows a remote, unauthenticated attacker to send crafted requests to the internet-facing portal. By exploiting this vulnerability, an attacker can direct the appliance to issue requests on their behalf, enabling them to reach internal functionality and perform unauthorized operations. SonicWall released hotfixes in October 2026 to address the issue, urging users to update their systems. At the time of the announcement, the vendor stated there was no evidence that the vulnerability was being actively exploited in the wild.

Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Source
PSIRT@sonicwall.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

PSIRT@sonicwall.com
CWE-441

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. CVE-2026-102255 is a CVSS 10.0 pre-auth SSRF flaw in SonicWall SMA 1000. Unauthenticated attackers could reach internal functionality and perform unauthorized operations. Apply the fixed platform hotfix now: https://t.co/8V5yIb764Y #SonicWall #CyberSecurity #CVE

    @SecPod

    9 Oct 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2025-70518 (CVSS: 10) CVE-2026-102255 (CVSS: 10) sonicwall CVE-2026-76482 (CVSS: 10) Cisco CVE-2025-70521 (CVSS: 9.8) CVE-2026-104334 (CVSS: 9.8) IBM ..🧵👇

    @exploitgrid

    8 Oct 2026

    162 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  3. CVE advisory: CVE-2026-102255 - sonicwall: SonicWall SMA1000 security advisory SNWLID-2026-0017. https://t.co/XeIlwEVnDI #CVE #CyberSecurity #SonicWall #SMA1000

    @vulnipulse

    8 Oct 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 SonicWall SMA1000 Appliance Hit by Four Critical Flaws (CVE-2026-102255 to CVE-2026-102258) Enabling Pre-Auth SSRF and Post-Auth RCE Critical Vulnerability Alert! SonicWall SMA1000 Appliance is affected by CVE-2026-102256. 🔍 Identify Targets via ZoomEye: Search Dork:

    @zoomeyebot

    7 Oct 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Warning: A critical SSRF vulnerability in #SonicWall SMA1000 lets unauthenticated attackers reach internal functions. #CVE-2026-102255 #CVE-2026-102256 #CVE-2026-102257 #CVE-2026-102258 CVSS(3.0): 10.0. Read the advisory https://t.co/NXaCyGIVzJ and #Patch #Patch #Patch

    @CCBalert

    7 Oct 2026

    242 Impressions

    2 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. 🚨 SONICWALL PATCHES CVSS 10.0 UNAUTHENTICATED SSRF IN SMA1000 REMOTE-ACCESS GATEWAYS (CVE-2026-102255) SonicWall released platform hotfixes on October 6, 2026 for a maximum-severity server-side request forgery flaw in its SMA1000 secure remote access appliances. • CVE: htt

    @DailyDarkWeb

    7 Oct 2026

    5727 Impressions

    3 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255): SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000… www.​helpnetsecurity.​com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-10

    @shah_sheikh

    7 Oct 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.