SonicWall NetExtender Linux Client Temp File Path Manipulation in Auto-Upgrade
CVE-2026-66153 Published on August 25, 2026

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

Vendor Advisory NVD

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-66153 has been classified to as an insecure temporary file vulnerability or weakness.


Products Associated with CVE-2026-66153

Want to know whenever a new CVE is published for SonicWall Netextender? stack.watch will email you.

 

Affected Versions

SonicWall NetExtender Version 10.3.5 and earlier versions is affected by CVE-2026-66153