CVE-2026-66153

Summary

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

Affected Software

VendorProductVersion RangeStatus
SonicWallNetExtender10.3.5 and earlier versionsaffected

Weaknesses

  • CWE-59: CWE-59 Improper link resolution before file access ('link following')

References