Yaamlabs
Vulnerabilities

SonicWall SMA1000: a third CVSS 10 SSRF, patch again

CVE-2026-102255 lets an unauthenticated attacker proxy requests through SMA1000 WorkPlace. September builds are affected. Fixed builds, probes and checks.

By Yaali. October 10, 2026, 6 min read, Vulnerabilities, Patching.

Cover illustration of a remote access gateway with a request line slipping through a side passage to an internal database, with the Yaamlabs logo and the text: SonicWall SMA1000 needs its third emergency patch this year, 10.0, CVSS, pre-auth SSRF in WorkPlace

SonicWall published advisory SNWLID-2026-0017 on October 6, fixing four vulnerabilities in its SMA1000 remote access appliances (models 6210, 7210 and 8200v). The worst, CVE-2026-102255, is a server-side request forgery (SSRF) flaw in the WorkPlace portal rated CVSS 10.0: an attacker with no account can make the appliance send requests on their behalf and reach functions that should only be available from inside it. The SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected.

This is the third pre-authentication SSRF rated 10.0 in SMA1000 WorkPlace this year, and the previous two were exploited before or as they were patched. The builds SonicWall shipped on September 1 to fix the second one are inside the affected range for this one, so an appliance that was patched last month is exposed again. SonicWall says it has no evidence of exploitation, but on October 9 a researcher reported honeypot traffic that matches the bug.

Request path for CVE-2026-102255: an unauthenticated OPTIONS request to the WorkPlace Extraweb interface is relayed by the appliance to its internal CouchDB service on 127.0.0.1 port 5984 and calls a design document's _rewrite function, above the three CVSS 10 WorkPlace SSRF flaws of 2026 (July, September and October) and Shadowserver's count of more than 400 exposed appliances

What was fixed

CVEFlawWhereLogin neededCVSS
CVE-2026-102255SSRF via an unintended alternate pathWorkPlace portalNone10.0
CVE-2026-102256OS command injection, can lead to code executionApplianceAdministrator7.8
CVE-2026-102257Zip Slip path traversal, can lead to code executionAppliance Management ConsoleAdministrator7.2
CVE-2026-102258Stored cross-site scriptingAppliance Management ConsoleAdministrator5.5

The three lower-rated flaws all need an administrator session. On their own they matter mainly if an admin account is already compromised. SonicWall has not said whether the SSRF can be chained with any of them, but the July and September attacks both paired an unauthenticated SSRF with an admin-level command execution bug, so treat the set as one fix.

How it works

WorkPlace is the user-facing portal of the SMA1000: the page remote staff log in to before they get their VPN tunnel or web application bookmarks. Behind it, the appliance runs internal services that listen only on the loopback address (127.0.0.1) and are never meant to see outside traffic.

An SSRF flaw turns the appliance into a relay. The attacker sends a request to the public portal, the portal forwards it to an address the attacker chooses, and the internal service trusts it because it arrives from the appliance itself. SonicWall classifies CVE-2026-102255 as both a classic SSRF (CWE-918) and an "unintended proxy" (CWE-441), and describes the cause as an "unintended alternate access path": a route through WorkPlace that skips the authentication the normal path enforces. SonicWall's CVSS vector marks the scope as changed, meaning the impact reaches beyond the vulnerable component, with high impact on confidentiality, integrity and availability.

The advisory does not name the internal functions that become reachable. The honeypot traffic described below gives the clearest public hint: the target is the appliance's own CouchDB database, a document store, which the payload tries to log in to as admin:admin. CouchDB's _rewrite handler, which the probes called, routes a request through rules stored in a database design document. If the relay works, that could let an attacker drive further database operations from one request; nobody has shown publicly what it achieves on an SMA1000.

What attackers are doing

SonicWall's position, as of its October 6 advisory, is that none of the four flaws is being exploited. CVE-2026-102255 is not in CISA's Known Exploited Vulnerabilities (KEV) catalog.

On October 9, Ryan Dewhurst of Previdian told BleepingComputer that the company's honeypots had recorded attempts consistent with the bug. The requests went to the WorkPlace Extraweb interface, used a crafted HTTP OPTIONS request to reach CouchDB at 127.0.0.1:5984, tried to traverse into a CouchDB design document and call its _rewrite function, and carried an HTTP Basic Authorization header for admin:admin. Previdian has not established whether those attempts would have compromised a real appliance, and no successful compromise has been reported.

The history argues for moving fast anyway. CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (7.2), disclosed July 14, were exploited for weeks before the fix to install malware, and CISA marks their ransomware use as known. CVE-2026-83548 (10.0) and CVE-2026-83549 (7.8), disclosed September 1, were also exploited and went into KEV on September 2. Shadowserver tracks more than 400 SMA1000 appliances reachable from the internet, without saying how many are patched.

What to do

Fixed SMA1000 builds 12.4.3-03670 and 12.5.0-03082 compared with the July and September fix builds that are now affected, followed by four steps: install the hotfix, cut exposure, check for probes and earlier compromise, rebuild and rotate if compromised

1. Install the platform hotfix

Affected builds are 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. Install 12.4.3-03670 or later, or 12.5.0-03082 or later, from MySonicWall. The appliance restarts after the hotfix, so plan a short outage for remote users. SonicWall lists no workaround.

Singapore's Cyber Security Agency (CSA) alert gives 12.4.3-03453 and 12.5.0-02835 as fixed. Those are the July fix builds and they fall inside the affected range, so use the builds above, which SonicWall, SecurityWeek and The Hacker News all give.

2. If you cannot patch today

There is no setting that closes the flaw. What you can do is reduce who reaches it. Put the WorkPlace portal behind an allow list of source countries or networks on the firewall in front of it if your user base allows that, and keep the Appliance Management Console (AMC) reachable only from an admin network, never from the internet. If WorkPlace is not needed from outside at all, block it until the hotfix is in.

3. Check for probes and earlier compromise

SonicWall has published no indicators of compromise for this advisory. Search the access logs on any reverse proxy, web application firewall or load balancer in front of the appliance for OPTIONS requests to WorkPlace that contain 127.0.0.1, 5984 or _rewrite, and for an Authorization header of Basic YWRtaW46YWRtaW4=, which is admin:admin encoded.

Because two earlier SSRF pairs were exploited, check for those too. For the July flaws, SonicWall advisory SNWLID-2026-0008, Rapid7 and Volexity published indicators. For the September flaws there are no public indicators, and SonicWall asks customers to open a case with Technical Support for an indicator review.

4. If you find signs of compromise

For the earlier waves, SonicWall's guidance was to re-image or redeploy the appliance rather than patch in place, change all user and administrator passwords, and reset TOTP (one-time password) tokens. Apply the same to any appliance with signs of this one, and review the identity providers and internal applications the SMA1000 can reach for logins from its address you cannot explain.

Patching the same box three times

An appliance patched on September 1 was back in the affected range on October 6. Asset inventories that record "patched for CVE-X" instead of the running build hide that, so track remote access appliances by build number against the vendor's current affected range, and recheck after every advisory. When a vendor fixes the same class of bug in the same component three times in four months, log and alert on WorkPlace traffic at the proxy in front of it as well, so the next probe shows up before the next advisory does.

Our attack surface management work tracks which remote access gateways you expose and what build they run, and our network penetration tests check what an attacker can reach once a gateway like this falls. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: SecurityWeek, The Hacker News, BleepingComputer, Rescana, CSA Singapore, SonicWall product notice, NHS England Digital.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.