CVE-2026-66153
SonicWall · NetExtender
A local file path manipulation vulnerability exists in the SonicWall NetExtender Linux client due to insecure handling of temporary files during the auto-upgrade process.
Executive summary
A high-severity local file path manipulation vulnerability in the SonicWall NetExtender Linux client allows a local user to potentially compromise system integrity and confidentiality.
Vulnerability
The vulnerability, classified as CWE-59, stems from improper link resolution during the NEService auto-upgrade process. This allows a low-privileged local attacker to manipulate file paths, potentially leading to unauthorized file access or modification.
Business impact
The vulnerability carries a CVSS score of 7.0, indicating a significant risk to organizational infrastructure. Successful exploitation could allow a local attacker to gain elevated privileges or access sensitive data, resulting in a breach of system confidentiality, integrity, and availability.
Remediation
Immediate Action: Upgrade the SonicWall NetExtender Linux client to a version beyond 10.3.5 as soon as the vendor releases a patched version.
Proactive Monitoring: Monitor system logs for unusual file access patterns or unexpected execution of scripts originating from temporary directories associated with the NetExtender service.
Compensating Controls: Restrict local user access to the directories used by the NetExtender auto-upgrade service to prevent unauthorized manipulation of temporary files.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for high-impact local compromise, administrators should prioritize updating the NetExtender client once a fix is confirmed available by SonicWall. Organizations should review their deployment of the Linux client and ensure that minimal user privileges are enforced on systems running the NetExtender service to reduce the attack surface.