Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality
SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.
Summary
SonicWall has published advisory SNWLID-2026-0017 addressing multiple issues in SMA 1000 series appliances. The most severe is CVE-2026-102255, a critical pre-authentication server-side request forgery (SSRF) flaw in the Work Place interface. An unauthenticated attacker can abuse an unintended alternate access path so the appliance issues requests on their behalf, reaches internal functionality, and performs unauthorized operations. SonicWall states there is currently no evidence that the vulnerabilities in this release are being exploited in the wild and strongly advises upgrading to a fixed platform-hotfix.
The same advisory also addresses CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258. Descriptions of those issues are in the official SonicWall advisory.
Vulnerability Details
| CVE ID | CVSS Score | Type |
|---|---|---|
| CVE-2026-102255 | 10.0 | CWE-918: Server-Side Request Forgery (SSRF) CWE-441: Unintended Proxy or Intermediary |
Technical Information
CVE-2026-102255 — Pre-authentication SSRF via Unintended Forward-Proxy
The flaw is in the SMA 1000 Appliance Work Place interface. SonicWall describes it as pre-authentication server-side request forgery caused by an unintended alternate access path. That path effectively allows the appliance to act as an unintended intermediary: a remote attacker can abuse it so the device issues HTTP requests on the attacker’s behalf.
Because those requests originate from the appliance, they can reach internal functionality that trusts the SMA 1000 and support unauthorized operations that would not normally be available without authentication. SonicWall classifies the weakness under server-side request forgery and unintended proxy or intermediary behavior.
The issue is specific to the SMA 1000 series Work Place surface. SonicWall states that SSL-VPN running on SonicWall firewall products is not affected, and that the SMA 100 Series product line is outside the affected set for this advisory. Physical and virtual SMA 1000 models in scope are 6210, 7210, and 8200v.
SonicWall reports no evidence that the vulnerabilities addressed in this release are being exploited in the wild at the time of publication. No workaround is provided; the published remediation is to upgrade to a fixed platform-hotfix.
Impact
-
Unauthenticated access to internal functionalityA remote attacker without credentials can coerce the SMA 1000 appliance to make requests that reach internal functions and support unauthorized operations on the device or trusted internal paths.
Affected Versions
Affected products and versions per SonicWall:
- SMA1000 models 6210, 7210, and 8200v — 12.4.3-03526 (platform-hotfix) and older
- SMA1000 models 6210, 7210, and 8200v — 12.5.0-02952 (platform-hotfix) and older
These issues do not affect SSL-VPN on SonicWall firewalls or the SMA 100 Series product line.
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic ID | Tactic |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | TA0001 | Initial Access |
| T1090 | Proxy | TA0011 | Command and Control |
Mitigation and Recommendations
SonicWall strongly advises SMA 1000 users to upgrade to a fixed platform-hotfix. No workaround is published for this advisory.
Fixed Builds
- SMA1000 models 6210, 7210, and 8200v — 12.4.3-03670 (platform-hotfix) and higher
- SMA1000 models 6210, 7210, and 8200v — 12.5.0-03082 (platform-hotfix) and higher
The latest platform-hotfix is available for download on mysonicwall.com.
Recommended Actions
- Upgrade affected SMA 1000 appliances to a fixed platform-hotfix listed above.
- Confirm the running build after upgrade in the appliance management interface.
- Limit unnecessary internet exposure of the Work Place interface where operationally possible until fixed software is in place.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




