Vulnerability record · CVE-2026-83548 · published 1 September 2026
CVE-2026-83548: SonicWall SMA1000 pre-auth SSRF via alternate access path
Sonicwall · Sma8200v
The SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication. A remote unauthenticated attacker can use it to reach sensitive internal functionality and perform unauthorized operations. Because it is pre-auth, network-reachable and rated critical, it is a high-value target for edge-appliance compromise.
Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication, network-reachable SSRF with CVSS 10.0 and confirmed KEV listing with a near-term remediation deadline.
What it is
The SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication. A remote unauthenticated attacker can use it to reach sensitive internal functionality and perform unauthorized operations. Because it is pre-auth, network-reachable and rated critical, it is a high-value target for edge-appliance compromise.
Impact
An attacker gains unauthorized access to sensitive functionality and can perform unauthorized operations through the appliance, potentially reaching internal services via forged requests. The scope change in the CVSS vector indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the Work Place interface with no authentication and no user interaction required (AV:N/PR:N/UI:N). The unintended alternate access path is the entry point; no credentials or victim action are needed.
Exploitation
CISA added it to KEV on 2026-09-02 with a remediation due date of 2026-09-05, indicating known exploitation. EPSS 30-day probability is 0.04667 (91st percentile); no ransomware campaign use is documented.
What to do
- Apply the SonicWall vendor fix per advisory SNWLID-2026-0016 immediately; treat the 2026-09-05 KEV due date as the deadline.
- If a patch is not yet available, follow CISA BOD 26-04 guidance: apply vendor mitigations or discontinue use of the exposed product.
- Remove or restrict internet exposure of the SMA1000 Work Place interface until patched.
- Restrict outbound traffic from the appliance to only required destinations to blunt SSRF reach into internal networks.
- Verify no unauthorized configuration or account changes were made before patching.
Detection
- Review appliance and perimeter logs for requests to the Work Place interface from unauthenticated or unexpected sources, especially to unusual paths.
- Monitor outbound connections originating from the SMA1000 to internal or unfamiliar external hosts for SSRF patterns.
- Alert on configuration changes, new accounts or administrative actions on the appliance outside change windows.
- Hunt for known exploitation indicators from vendor and CISA guidance for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548 | US Government Resource |
Track CVE-2026-83548 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-83548), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.