Deserialization of Untrusted Data Vulnerability in WatchGuard Fireware OS
CVE-2026-13046
7.5HIGH
What is CVE-2026-13046?
A vulnerability exists in WatchGuard Fireware OS's SAML single sign-on session handling, specifically affecting the samld service. This flaw allows an attacker with file write access on the appliance to execute arbitrary code. By crafting a malicious session file and forcing the samld service to load it, the attacker can gain unauthorized control, potentially leading to severe consequences for the integrity and availability of the system.
Affected Version(s)
Fireware OS Default 2026.3 < 2026.3.2
Fireware OS Default 2025.0 < 2026.2.3
Fireware OS Default 12.0 < 12.12.3
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Nicholas Zubrisky (@NZubrisky) of TrendAI Research
