Path Traversal Vulnerability in Fireware OS WebUI Management Agent by WatchGuard
CVE-2026-13224
8.2HIGH
What is CVE-2026-13224?
A vulnerability in the WebUI management agent of Fireware OS enables authenticated administrators to exploit path traversal techniques, potentially leading to unauthorized access to sensitive files on the local filesystem. By crafting specific management requests, attackers can circumvent access controls and read or list files that should remain protected, posing a serious risk to the integrity and confidentiality of the system.
Affected Version(s)
Fireware OS 12.0 < 12.5.21
Fireware OS Default 2026.3 < 2026.3.2
Fireware OS Default 2025.0 < 2026.2.3
