CVE-2026-78328

A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

  • Published Sep 4, 2026
  • CVSS 9.1 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78328 at the National Vulnerability Database