Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Temporary File Handling in SonicWall NetExtender Auto‑Upgrade Path Traversal |
Tue, 25 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonicwall
Sonicwall netextender |
|
| Vendors & Products |
Sonicwall
Sonicwall netextender |
Tue, 25 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths. | |
| Weaknesses | CWE-59 | |
| References |
|
Status: PUBLISHED
Assigner: sonicwall
Published:
Updated: 2026-08-25T20:01:15.598Z
Reserved: 2026-07-24T08:34:11.798Z
Link: CVE-2026-66153
No data.
Status : Received
Published: 2026-08-25T20:17:01.270
Modified: 2026-08-25T20:17:01.270
Link: CVE-2026-66153
No data.
OpenCVE Enrichment
Updated: 2026-08-25T22:15:04Z
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')