ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability
WatchGuard Fireware OS samld deserialization flaw CVE-2026-13046 can yield remote code execution after a write precondition.
ZDI-26-749 covers deserialization of untrusted data in WatchGuard Fireware OS samld SAMLSession handling. A remote attacker who can already write to the samld session directory can execute arbitrary code. ZDI assigned CVE-2026-13046 and a CVSS score of 7.5. The published advisory does not report in-the-wild exploitation.
- Unsafe deserialization in Fireware OS samld SAMLSession handling
- Exploit requires write access to the samld session directory
- Successful exploitation leads to remote code execution
- CVE-2026-13046 is rated CVSS 7.5; no active exploitation stated
Vulnerabilities mentionedAll →
- CVE-2026-130467.5—Deserialization code execution in WatchGuard Fireware samldpublished · WatchGuard Fireware OS (SAML SSO session handler samld)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13046 | Deserialization code execution in WatchGuard Fireware samld WatchGuard Fireware OS has a deserialization-of-untrusted-data flaw (CWE-502) in its SAML single sign-on session handler, samld. An attacker who can already write files on the appliance can plant a crafted session file and cause samld to load it, which runs arbitrary code in the samld service. CVSS 4.0 rates the issue 7.5 (high), with high impact to confidentiality, integrity, and availability on the device; network access is listed, but attack requirements are present and high privileges are required, so this is a follow-on bug rather than a standalone unauthenticated remote exploit. The affected product is WatchGuard Fireware OS; no version range is given in the advisory data. There is no known public proof of concept, and the CVE is not in CISA’s Known Exploited Vulnerabilities catalog. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.
This source does not provide full text. Read it at zerodayinitiative.com.