CVE-2026-102255 is a pre-authentication server-side request forgery vulnerability in the SonicWall SMA1000 Appliance WorkPlace interface. An unintended alternate access path allows a remote unauthenticated attacker to make the appliance act as a forward proxy, potentially reaching internal functionality and performing unauthorized operations. Affected models include SMA 6210, SMA 7210, and SMA 8200v running platform-hotfix 12.4.3-03526 or earlier in the 12.4.3 branch, or 12.5.0-02952 or earlier in the 12.5.0 branch. SonicWall firewall SSL-VPN services and SMA 100 Series appliances are not affected. Honeypots detected crafted HTTP OPTIONS requests targeting the appliance's internal CouchDB service, but successful compromise has not been confirmed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
99 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A maximum-severity, pre-authentication SSRF vulnerability in SonicWall SMA1000 Appliance Work Place allows unauthenticated attackers to proxy requests to internal services. MFA does not prevent this access path. Internal CouchDB access could enable root-level code execution using techniques demonstrated in a previous vulnerability chain; the cited public Metasploit module is for that earlier chain, not explicitly this CVE. Previously patched September firmware remains vulnerable.
A maximum-severity vulnerability in the SonicWall SMA1000 Appliance WorkPlace interface allows remote unauthenticated attackers to make the appliance issue requests on their behalf, potentially accessing internal functionality and performing unauthorized operations. Observed attempts targeted CouchDB at 127.0.0.1:5984, invoking a design document's _rewrite function with admin:admin credentials. SonicWall patched the flaw, although its advisory had not yet acknowledged active exploitation.
A pre-authentication SSRF vulnerability in SonicWall SMA 1000's Work Place interface. An unauthenticated remote attacker could exploit an alternate access path to make the appliance issue requests, reach internal functionality, and perform unauthorized operations. The plugin identifies this CVE as the source of its critical CVSS v2 score of 10.0. Detection relies on the application's self-reported version rather than testing exploitation.
A critical pre-authentication SSRF vulnerability caused by an unintended alternate access path in the SonicWall SMA1000 WorkPlace interface. An unauthenticated remote attacker can cause the appliance to issue requests on their behalf, potentially accessing internal functionality and performing unauthorized operations. Affected releases are 12.4.3-03526 and earlier and 12.5.0-02952 and earlier. SonicWall provides fixes in 12.4.3-03670 and later and 12.5.0-03082 and later. At disclosure, SonicWall reported no evidence of exploitation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.