Home

Description

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

PUBLISHED Reserved 2026-03-03 | Published 2026-03-31 | Updated 2026-03-31 | Assigner sonicwall

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unknown

10.0.34.8215 and earlier versions
affected

10.0.34.8223 and earlier versions
affected

Credits

Brian Mariani of DigitalCanion SA - www.digitalcanion.com finder

References

psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0002 vendor-advisory

cve.org (CVE-2026-3468)

nvd.nist.gov (CVE-2026-3468)

Download JSON