CVE Tools

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

In plain language

AI Act now

CVE-2026-83548 is a serious security hole in SonicWall SMA1000’s “Work Place” interface that lets an attacker send the device to access other systems without logging in—so if your SMA1000 has Work Place enabled and is reachable, you should act immediately.

Executive summary

Unauthenticated SSRF in the SonicWall SMA1000 Appliance Work Place interface allows pre-auth network-triggered requests to arbitrary or restricted internal/unauthorized targets via an unintended alternate access path.

If affected, business impact
Unauthorized access to management functionsExposure of internal network resourcesService disruption riskPotential device compromise leading to takeover

What to do now

  1. Check whether your SonicWall SMA1000 has the Work Place interface enabled.
  2. Check whether the SMA1000 is reachable from the internet on the Work Place-related network paths (external IPs/port forwarding/firewall rules/load balancers).
  3. If Work Place is enabled and the device is internet-reachable, treat this as actively exploited and apply SonicWall’s mitigations immediately; if no mitigation is available for your version, discontinue use until you can mitigate.
  4. Confirm your environment is updated to the fixed guidance provided by SonicWall for SMA1000; if no fixed version is available, implement the vendor’s stated compensating controls (and block/restrict external access to Work Place paths).
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Sep 2, 2026
Remediation due:Sep 5, 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Command and Control
Initial Access
View detailed technique mapping

References

8

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-83548 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows