VDB

GCVE-110-NCSC-2026-404

GCVE-110-NCSC-2026-404
Advisory PublishedCVSS 2.9/10
Vulnetix · Advisory published October 7, 2026
A vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling allows attackers with file write access to execute arbitrary code by loading a malicious session file.

Weaknesses (CWE)

CWE-502Deserialization of Untrusted DataCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-770Allocation of Resources Without Limits or ThrottlingCWE-121Stack-based Buffer OverflowCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-863Incorrect AuthorizationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-409Improper Handling of Highly Compressed Data (Data Amplification)CWE-176Improper Handling of Unicode EncodingCWE-306Missing Authentication for Critical FunctionCWE-476NULL Pointer DereferenceCWE-295Improper Certificate ValidationCWE-191Integer Underflow (Wrap or Wraparound)CWE-1284Improper Validation of Specified Quantity in InputCWE-352Cross-Site Request Forgery (CSRF)CWE-125Out-of-bounds ReadCWE-862Missing Authorization

Risk Scores

CVSS 3.1
2.9/10
Low · CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersionsPlatforms
WatchGuardvers:unknown/*——

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,384 records in the GCVE database · Updated October 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›