SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow an attacker to write arbitrary files with root privileges.
The issues affect NetExtender Linux Client versions 10.3.5 and earlier; the fixed release is version 10.3.6 and later. Tracked as CVE-2026-66152, the more severe vulnerability received a CVSS score of 8.8.
SonicWall said the issue lies in how the Linux client handles an OPSWAT tarball. A remote attacker could exploit path traversal sequences to place files outside the intended extraction directory.
Because the affected operation runs with root privileges, successful exploitation could allow arbitrary file writes as root. This can create a serious escalation path on Linux systems, depending on where an attacker can write files and how those files are later used by the operating system or installed software.
For example, an attacker may attempt to overwrite configuration files, place malicious scripts in locations accessed by privileged processes, or alter startup-related files.
The final impact depends on the target environment, file permissions, and whether a victim can be persuaded to interact with a malicious update or archive.
SonicWall NetExtender Vulnerabilities
The vulnerability is classified as CWE-29, Path Traversal, which covers attacks that use special path sequences, such as ..\ to escape a target directory. In archive extraction scenarios, unsafe handling of file paths can allow crafted entries to write to unexpected locations on a system.
SonicWall also addressed CVE-2026-66153, a separate improper link resolution vulnerability in the NetExtender Linux client. The flaw affects the NEService auto-upgrade process, which handles temporary files insecurely.
A local attacker with access to the device could manipulate file paths via symbolic links, potentially influencing where files are accessed or written.
CVE-2026-66153 carries a CVSS score of 7.0 and is categorized as CWE-59, Improper Link Resolution Before File Access, commonly known as a symlink-following issue.
Such flaws can become dangerous when privileged software performs file operations in attacker-controlled or predictable temporary locations. The first issue has a network attack vector and requires user interaction, according to SonicWall’s advisory.
The second is a local attack that requires low privileges and high attack complexity. Both vulnerabilities can affect confidentiality, integrity, and availability if successfully exploited.
SonicWall said there is currently no evidence that either vulnerability has been exploited in the wild. However, NetExtender is widely used to provide remote access to corporate environments, making rapid patching important for organizations that deploy the Linux client.
The vulnerabilities are documented in SonicWall advisory SNWLID-2026-0013, published on August 25, 2026. No workaround is available.
Administrators should upgrade affected NetExtender Linux Client installations from version 10.3.5 or earlier to version 10.3.6 or later.
Security teams should also identify unmanaged Linux endpoints, verify installed client versions, and review privileged software update mechanisms for unsafe archive extraction and temporary-file handling. SonicWall confirmed that Windows-based NetExtender client versions are not affected by these vulnerabilities.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
