---
cve: "CVE-2026-66147"
severity: "CRITICAL"
cvss: 9.4
epss: "1.1%"
vendor: "SonicWall"
kev: false
exploited: false
published: "2026-08-11 21:17:49"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T10:59:16+02:00"
---

# CVE-2026-66147

> 9.4 CRITICAL

## Beschreibung

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-66147) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
