CVE-2026-4114
Undergoing Analysis
Undergoing Analysis - In Progress
Authentication Bypass via Unicode Handling in SonicWall SMA
Publication date: 2026-04-09
Last updated on: 2026-05-10
Assigner: SonicWALL, Inc.
Description
Description
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sonicwall | sma1000 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-176 | The product does not properly handle when an input contains Unicode encoding. |