LDAP injection in Fireware OS - CVE-2026-1498

 

LDAP injection in Fireware OS - CVE-2026-1498

Published: January 30, 2026


Vulnerability identifier: #VU122143
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1498
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper input validation when processing DLAP queries. A remote non-authenticated attacker can send a specially crafted LDAP query to the application via an exposed authentication or management interface, bypass authentication process and gain unauthorized access to the application.


Affected software

Fireware OS

How to mitigate CVE-2026-1498

Install updates from vendor's website.

Fireware OS - addressed in versions 12.5.16, 12.11.7, 2026.1

External References

Related Security Bulletins