{"id":"CVE-2026-4315","title":"A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into v…","summary":"A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into v…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-352"],"vendor":"watchguard","product":"fireware","affected":["fireware >= 2025.1, < 2026.2","fireware >= 12.5, < 12.5.18","fireware >= 11.8, < 11.12.4","fireware = 11.12.4","fireware >= 12.0, < 12.12"],"patched":["fireware 12.12"],"published":"2026-03-30","updated":"2026-08-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4315","references":[{"url":"https://psirt.watchguard.com/CVE-2026-4315","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"},{"url":"https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00006","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"}],"tags":["nvd"],"epss":0.00165,"epssPercentile":0.06125,"ingestedAt":"2026-08-14T14:18:32.507Z","slug":"CVE-2026-4315","body":"## Overview\n\nA Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.\n\n## Affected\n\n- `fireware >= 2025.1, < 2026.2`\n- `fireware >= 12.5, < 12.5.18`\n- `fireware >= 11.8, < 11.12.4`\n- `fireware = 11.12.4`\n- `fireware >= 12.0, < 12.12`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fireware 12.12`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}