---
id: CVE-2026-13046
title: >-
  A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's
  SAML single sign-on session handling (samld) allows an attacker who has
  already obtained the ability to write files on the appliance to execute
  arbitrary code …
summary: >-
  A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's
  SAML single sign-on session handling (samld) allows an attacker who has
  already obtained the ability to write files on the appliance to execute
  arbitrary code …
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-502
vendor: WatchGuard
product: Fireware OS
affected:
  - fireware_os >= 2026.3 < 2026.3.2
  - fireware_os >= 2025.0 < 2026.2.3
  - fireware_os >= 12.0 < 12.12.3
  - fireware_os >= 12.11 < 12.11.10
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T00:16:35.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13046'
references:
  - url: 'https://psirt.watchguard.com/CVE-2026-13046'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T23:52:50.543Z'
---

## Overview

A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
