Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 02 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.This issue affects Fireware OS: from 12.0 through 12.11.6, from 12.5 through 12.5.15, from 2025.1 through 2026.0. | |
| Title | WatchGuard Firebox LDAP Injection | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-90 | |
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0 cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5 cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1 |
|
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-02-02T16:32:46.653Z
Reserved: 2026-01-27T17:23:30.578Z
Link: CVE-2026-1498
Updated: 2026-01-30T14:13:22.731Z
Status : Deferred
Published: 2026-01-30T13:15:54.560
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-1498
No data.
OpenCVE Enrichment
Updated: 2026-04-18T01:15:05Z