HTTP Header Injection in SonicOS Allows Host Header Manipulation
CVE-2026-0516 Published on August 5, 2026
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
Vulnerability Analysis
CVE-2026-0516 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Neutralization of HTTP Headers for Scripting Syntax
The application does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
Products Associated with CVE-2026-0516
Want to know whenever a new CVE is published for SonicWall Sonicos? stack.watch will email you.
Affected Versions
SonicWall SonicOS:- Version 6.5.5.2-28n and older versions is affected.
- Version 7.0.1-5169 and older versions is affected.
- Version 7.3.3-7015 and older versions is affected.
- Version 8.2.1-8010 and older versions is affected.