CVE-2026-66152
8.8SonicWall · NetExtender
A path traversal vulnerability in the OPSWAT tarball component of the SonicWall NetExtender Linux client allows an unauthenticated attacker to write arbitrary files with root privileges.
Executive summary
A high-severity path traversal vulnerability in SonicWall NetExtender for Linux allows unauthenticated attackers to execute arbitrary file writes as root, posing a critical risk to system integrity.
Vulnerability
This path traversal flaw exists within the OPSWAT tarball processing logic of the NetExtender client. The vulnerability can be triggered by an unauthenticated attacker via a malicious tarball, resulting in arbitrary file write operations with root level permissions.
Business impact
The ability for an attacker to write arbitrary files as root allows for complete system compromise, including the installation of backdoors, escalation of privileges, or the destruction of critical system data. Given the CVSS score of 8.8, this vulnerability represents a significant threat to organizational security, as it grants an attacker the ability to bypass standard system security controls and gain persistent access to affected Linux endpoints.
Remediation
Immediate Action: Review the official SonicWall PSIRT advisory (SNWLID-2026-0013) and apply the latest security updates provided by the vendor as soon as they are released.
Proactive Monitoring: Monitor system logs for unauthorized file modification attempts or unexpected process execution patterns originating from the NetExtender client service.
Compensating Controls: Restrict access to the network environment where NetExtender clients are deployed and ensure that endpoints are running with the principle of least privilege where possible.
Exploitation status
Public Exploit Available: No (Exploit available: false)
Analyst recommendation
Due to the potential for full system takeover, administrators should prioritize the remediation of this vulnerability across all Linux environments utilizing the NetExtender client. Monitor the SonicWall PSIRT portal consistently for the release of a patch and ensure that all affected instances are updated immediately upon availability to prevent potential exploitation.