HarborGuard / CVE
Back to search
HIGHCVE-2026-3987Published Modified CNA WatchGuard

CVE-2026-3987: WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.This issue affects Fireware OS 12.6.1 up to and including 12.11.8 and 2025.1 up to and including 2026.1.2.

Metrics

CVSS v4.0
8.6
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • WatchGuard / Fireware OS
    ≤ 12.11.8 · ≤ 2026.1.2
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References
CVE-2026-3987: WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI | HarborGuard CVE