Deserialization of Untrusted Data Vulnerability in WatchGuard Fireware OS
CVE-2026-13046

7.5HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
29 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-13046?

A vulnerability exists in WatchGuard Fireware OS's SAML single sign-on session handling, specifically affecting the samld service. This flaw allows an attacker with file write access on the appliance to execute arbitrary code. By crafting a malicious session file and forcing the samld service to load it, the attacker can gain unauthorized control, potentially leading to severe consequences for the integrity and availability of the system.

Affected Version(s)

Fireware OS Default 2026.3 < 2026.3.2

Fireware OS Default 2025.0 < 2026.2.3

Fireware OS Default 12.0 < 12.12.3

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicholas Zubrisky (@NZubrisky) of TrendAI Research
.