CVE-2026-83548 is a pre-authentication SSRF vulnerability in the SonicWall SMA1000 Work Place interface, exploitable remotely without authentication or user interaction, with a maximum CVSS score of 10.0. It is actively exploited in the wild and listed in CISA KEV, allowing unauthenticated attackers to reach internal sensitive functionality via an unintended alternate access path, effectively compromising the appliance itself.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-01
Added to CISA KEV: 2026-09-02 1 DAY BETWEEN CVE AND KEV
CVE-2026-83548 is a critical, pre-authentication Server-Side Request Forgery (SSRF) vulnerability affecting the Work Place interface of SonicWall SMA 1000 series appliances [2][4]. This flaw arises from an unintended alternate access path within the appliance's interface, allowing remote, unauthenticated attackers to interact with internal, sensitive functionality [1][8]. With a CVSS score of 10.0, it represents a severe security risk that enables unauthorized operations, potentially compromising the integrity and security of both the appliance and the connected internal network [2][7].
CVE info copied to clipboard. Summary. Pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface due to an unintended alternate access path that allows unauthorized access to sensitive functionality. Impact. An unauthenticated attacker over the network can exploit this SSRF…
On September 1, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-83548 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface. According…
Re-image (hardware) or re-deploy (virtual) appliances. Change all user and administrator passwords. Reset TOTP tokens. SonicWall strongly advises Secure Mobile Access customers on affected versions follow the guidance provided. Related information SNWLID-2026-0016 CVE-2026-83548 CVE-2026-83549 How t…
CVE-2026-83548 is a significant vulnerability identified in the SonicWall SMA1000 Appliance Work Place Interface, specifically characterized as a Server-Side Request Forgery (SSRF) issue. This vulnerability arises due to an unintended alternate access path that allows remote unauthenticated attacker…
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. ... CVE-2026-83548 Detail Description A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate a…