CVE-2026-13046: Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution
A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.11.10
Event History
Frequently Asked Questions
What level of access does an attacker need before this can be exploited?
The attacker must already be able to write files on the Fireware OS appliance. They then need to place a maliciously crafted SAML session file where the samld service will load it.
What privileges would successful exploitation provide?
Successful exploitation allows arbitrary code execution in the context of the samld service.