Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution
Summary
| CVE | CVE-2026-86131 |
|---|---|
| State | PUBLISHED |
| Assigner | WatchGuard |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-30 00:16:36 UTC |
| Updated | 2026-10-01 18:17:28 UTC |
| Description | A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox. |
Risk And Classification
Primary CVSS: v4.0 9.2 CRITICAL from 5d1c2695-1a31-4499-88ae-e847036fd7e3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-94 | CWE-295 | CWE-829 | CWE-295 CWE-295 | CWE-829 CWE-829 | CWE-94 CWE-94
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | Secondary | 9.2 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 9.2 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WatchGuard | Fireware OS | affected 2026.3 2026.3.2 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 2025.0 2026.2.3 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.12.3 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.5.21 custom | T15/T35 |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| psirt.watchguard.com/CVE-2026-86131 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | psirt.watchguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: btaol (en)
Additional Advisory Data
Solutions
CNA: Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Exploits
CNA: WatchGuard is not aware of any exploitation of this vulnerability in the wild.
There are currently no legacy QID mappings associated with this CVE.