AI analysis
WatchGuard Fireware OS has a deserialization-of-untrusted-data flaw (CWE-502) in its SAML single sign-on session handler, samld. An attacker who can already write files on the appliance can plant a crafted session file and cause samld to load it, which runs arbitrary code in the samld service. CVSS 4.0 rates the issue 7.5 (high), with high impact to confidentiality, integrity, and availability on the device; network access is listed, but attack requirements are present and high privileges are required, so this is a follow-on bug rather than a standalone unauthenticated remote exploit. The affected product is WatchGuard Fireware OS; no version range is given in the advisory data. There is no known public proof of concept, and the CVE is not in CISA’s Known Exploited Vulnerabilities catalog.
What to do: Apply WatchGuard’s Fireware OS fix for CVE-2026-13046 as soon as a vendor build is available; affected version ranges are not stated in this data, so match the advisory rather than guessing a release. Until then, tightly limit who and what can write files on the appliance, restrict management access, and review appliances for unexpected SAML session files or unusual samld behavior. Treat any successful use of this bug as a sign of an earlier file-write foothold and investigate that compromise.
Affected
| WatchGuard Fireware OS (SAML SSO session handler samld) | — |
Estimated exposure
largeOn the order of 10,000–100,000 Fireware appliances potentially in scope (rough estimate; confirmed affected versions unknown) — Rough estimate from WatchGuard Firebox/Fireware being a widely deployed SMB and enterprise firewall family, with public internet scans historically showing on the order of tens of thousands of reachable devices and more units on internal…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.