CVE-2026-66154
Awaiting Analysis Awaiting Analysis - Queue

Insufficient Certificate Validation in GMS Application

Vulnerability report for CVE-2026-66154, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: SonicWALL, Inc.

Description

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sonicwall gms to 9.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient certificate validation in a privileged communication workflow of a GMS application version 9.5.1 (Build 9510.1044) and earlier. It allows unauthorized changes under a successful man-in-the-middle (MitM) attack with controlled network conditions.

Detection Guidance

This vulnerability involves insufficient certificate validation in SonicWall GMS versions 9.5.1 (Build 9510.1044) and earlier. Detection requires checking for outdated versions and monitoring network traffic for potential MitM attacks. Use commands like 'openssl s_client -connect [target]:[port]' to inspect certificates and 'nmap -sV --script ssl-cert [target]' to verify SSL/TLS configurations.

Impact Analysis

This vulnerability could permit attackers to intercept and alter sensitive communications due to weak certificate validation. It may lead to unauthorized access, data breaches, or manipulation of system configurations, especially in privileged workflows.

Compliance Impact

This vulnerability could violate compliance requirements that mandate secure communication and data integrity, such as GDPR (data protection) and HIPAA (health information security). Insufficient validation may lead to unauthorized access or data leaks, risking regulatory penalties.

Mitigation Strategies

Update the GMS application to the latest version to address the insufficient certificate validation issue. Ensure network monitoring for unusual changes or unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66154. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart