CVE-2026-86131
CVE-2026-86131
9.2
CriticalPublished:
Last updated:
Source:5d1c2695-1a31-4499-88ae-e847036fd7e3
Analyzed
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- Present
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
References
5d1c2695-1a31-4499-88ae-e847036fd7e3
https://psirt.watchguard.com/CVE-2026-86131