CVE-2026-1498

WatchGuard Firebox LDAP Injection

High 7.0 CVSS v4.0 › Published 2026-01-30Updated 2026-08-24

Summary #

An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 2025.1, < 2026.1, >= 12.0, < 12.11.7>= 2026.1, >= 12.11.7
T15/T35 >= 12.0, < 12.5.16>= 12.5.16

Weakness Type and Impact #

  • CWECWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
  • CAPECCAPEC-136LDAP Injection

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Fireware OS 2026.1, Fireware OS 12.11.7, Fireware OS 12.5.16

References #

Credits #

  • Discovered internally by WatchGuardfinder