CVE-2026-1498
WatchGuard Firebox LDAP Injection
CVSS Score
0.0
EPSS Score
0.7%
EPSS Percentile
49th
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.
| CWE | CWE-90 |
| Vendor | watchguard |
| Product | fireware os |
| Published | Jan 30, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard fireware os
Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Fireware OS
2025.1 < 2026.1 12.0 < 12.11.7
WatchGuard / Fireware OS
12.0 < 12.5.16
References
Credits
Discovered internally by WatchGuard