Junglewise Threat Intelligence

CVE-2026-13728: WatchGuard Fireware OS hard-coded encryption key in FireCluster Access Portal

CVE-2026-13728 · Severity: info · CVSS 5.9 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Firebox appliances configured in a high-availability cluster (FireCluster) may use a hard-coded encryption key to protect stored user credentials for the Access Portal. Under specific exceptional circumstances, this could allow an attacker with administrative access to decrypt and steal saved passwords for internal resources. This issue only affects clustered devices using the Access Portal feature; standalone devices are not impacted.

Technical details

A Use of Hard-coded Credentials (CWE-798) vulnerability exists in WatchGuard Fireware OS when deployed in a FireCluster configuration. Under exceptional circumstances, the system may fall back to a hard-coded encryption key when securing the Access Portal resource credential database. An attacker with high privileges (PR:H) could potentially leverage this known key to decrypt stored credentials. The vulnerability is limited to clustered environments using the Access Portal; standalone Fireboxes are unaffected. Patches are available in Fireware OS versions 12.12.1 and 2026.2.1.

Affected products

  • WatchGuard Fireware OS 12.0 to 12.12, 2025.1 to 2026.2

Timeline

  • 2026-07-02: advisory: Initial advisory published by WatchGuard (WGSA-2026-00025)
  • 2026-07-02: patched: Fixed in versions 12.12.1 and 2026.2.1

References

Related threats