CVE-2026-13224
Received Received - Intake

Path Traversal in Fireware OS WebUI Management Agent

Vulnerability report for CVE-2026-13224, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WatchGuard Technologies, Inc.

Description

A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 12.0 (inc) to 12.5.21 (exc)
watchguard fireware_os 2026.3.2
watchguard fireware_os 2026.2.3
watchguard fireware_os 12.12.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Fireware OS WebUI management agent. An authenticated administrator can exploit it by sending a specially crafted request to read or list arbitrary files on the local filesystem. It affects Fireware OS versions 12.0 and later but below 12.5.21, 2026.3.2, 2026.2.3, and 12.12.3.

Detection Guidance

Since this is a path traversal vulnerability in Fireware OS WebUI, detection requires checking Fireware OS versions. Verify if your system runs versions 12.0 or later but below 12.5.21, 2026.3.2, 2026.2.3, or 12.12.3. Use the WebUI or CLI to check the version. No specific commands are provided in the resources.

Impact Analysis

An attacker with admin access could read sensitive files on the system, potentially exposing confidential data or system configurations. This could lead to further attacks or unauthorized access if exploited.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations that mandate strict data protection and access controls.

Mitigation Strategies

Immediately update Fireware OS to the patched versions: 12.5.21, 2026.3.2, 2026.2.3, or 12.12.3. Ensure only trusted administrators have access to the WebUI management interface to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13224. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart