Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 2025.1, < 2026.2 |
| Watchguard | Firebox M295 | - |
| Watchguard | Firebox M395 | - |
| Watchguard | Firebox M495 | - |
| Watchguard | Firebox M595 | - |
| Watchguard | Firebox M695 | - |
| Watchguard | Firebox T115-W | - |
| Watchguard | Firebox T125 | - |
| Watchguard | Firebox T125-W | - |
| Watchguard | Firebox T145 | - |
| Watchguard | Firebox T145-W | - |
| Watchguard | Firebox T185 | - |
| Watchguard | Firebox T15 | - |
| Watchguard | Firebox T35 | - |
| Watchguard | Firebox Cloud | - |
| Watchguard | Firebox M270 | - |
| Watchguard | Firebox M290 | - |
| Watchguard | Firebox M370 | - |
| Watchguard | Firebox M390 | - |
| Watchguard | Firebox M440 | - |
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2026-4315Broken Link
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00006Vendor Advisory
FAQ
What is CVE-2026-4315?
CVE-2026-4315 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing ...
How severe is CVE-2026-4315?
CVE-2026-4315 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4315?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox M295, Watchguard Firebox M395, Watchguard Firebox M495, Watchguard Firebox M595.