Junglewise Threat Intelligence

CVE-2026-13373: WatchGuard Fireware OS Stored XSS in Tigerpaw Technology Integration

CVE-2026-13373 · Severity: info · CVSS 4.8 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS, the operating system for Firebox network security appliances, contains a security vulnerability in its Tigerpaw Technology Integration module. An attacker with high-level administrative privileges can inject malicious scripts into the management interface. If another administrator views the affected configuration page, the script could execute, potentially leading to unauthorized actions or session hijacking within the management console.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Tigerpaw Technology Integration module of WatchGuard Fireware OS due to improper neutralization of input during web page generation. The vulnerability requires high privileges (PR:H) to exploit, as an attacker must be able to modify the Tigerpaw configuration. Once malicious input is stored, it executes when a victim user (typically another administrator) interacts with the affected management page. This issue represents an additional attack path for a previously identified vulnerability (CVE-2025-13936). Fixed versions include 2026.2.1 and 12.12.1.

Affected products

  • WatchGuard Fireware OS 12.4 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00015
  • 2026-07-03: disclosed: CVE published to NVD

References

Related threats