Description
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.This issue affects Fireware OS: from 12.0 through 12.11.6, from 12.5 through 12.5.15, from 2025.1 through 2026.0.
Published: 2026-01-30
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote LDAP Injection leading to Information Disclosure
Action: Patch
AI Analysis

Impact

An LDAP Injection flaw in WatchGuard Fireware OS allows a remote unauthenticated attacker to retrieve sensitive data from a connected LDAP authentication server via the exposed authentication or management web interface. The injection can also be leveraged to authenticate as an LDAP user with a partial identifier if the attacker already possesses that user’s passphrase. This vulnerability is rooted in improper input validation in LDAP queries, exposing confidentiality and potentially authorizing malicious access.

Affected Systems

The affected system is WatchGuard Fireware OS. Vulnerable releases include versions 12.0 through 12.11.6, 12.5 through 12.5.15, and 2025.1 through 2026.0.

Risk and Exploitability

The CVSS base score is 7, indicating high severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is still low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a remote attacker sending crafted LDAP search strings via the unauthorized web interface, gaining access to sensitive entries or authenticating as a user. No authentication is required to trigger the injection, increasing the potential impact on organizations that expose these interfaces publicly.

Generated by OpenCVE AI on April 18, 2026 at 01:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a Fireware OS release that includes the patch for CVE‑2026‑1498
  • Restrict unauthenticated access to the authentication and management web interfaces from external networks
  • Implement firewall or ACL rules to block or filter LDAP request traffic that originates from untrusted sources

Generated by OpenCVE AI on April 18, 2026 at 01:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 02 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
Description An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.This issue affects Fireware OS: from 12.0 through 12.11.6, from 12.5 through 12.5.15, from 2025.1 through 2026.0.
Title WatchGuard Firebox LDAP Injection
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-90
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-02-02T16:32:46.653Z

Reserved: 2026-01-27T17:23:30.578Z

Link: CVE-2026-1498

cve-icon Vulnrichment

Updated: 2026-01-30T14:13:22.731Z

cve-icon NVD

Status : Deferred

Published: 2026-01-30T13:15:54.560

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T01:15:05Z

Weaknesses