A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote… (CVE-2026-86131)
A code injection vulnerability exists in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling. An attacker who controls the remote VPN server can exploit this flaw to execute arbitrary commands with root privileges on the connecting Firebox device. This vulnerability is critical due to the high impact of remote code execution with elevated privileges.
AI Analysis
Technical Summary
CVE-2026-86131 describes a code injection vulnerability in the BOVPN Over TLS client configuration handling of WatchGuard Fireware OS. The flaw allows an attacker controlling the remote VPN server to execute arbitrary commands as root on the Firebox device when it connects to the malicious server. This vulnerability enables full system compromise remotely without requiring prior authentication.
Potential Impact
Successful exploitation results in remote code execution with root privileges on the Firebox device, potentially allowing full control over the affected system. This could lead to unauthorized access, data compromise, and disruption of network security functions.
Mitigation Recommendations
No patch or official fix information is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, avoid connecting Firebox devices to untrusted or potentially malicious VPN servers.
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote… (CVE-2026-86131)
Description
A code injection vulnerability exists in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling. An attacker who controls the remote VPN server can exploit this flaw to execute arbitrary commands with root privileges on the connecting Firebox device. This vulnerability is critical due to the high impact of remote code execution with elevated privileges.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86131 describes a code injection vulnerability in the BOVPN Over TLS client configuration handling of WatchGuard Fireware OS. The flaw allows an attacker controlling the remote VPN server to execute arbitrary commands as root on the Firebox device when it connects to the malicious server. This vulnerability enables full system compromise remotely without requiring prior authentication.
Potential Impact
Successful exploitation results in remote code execution with root privileges on the Firebox device, potentially allowing full control over the affected system. This could lead to unauthorized access, data compromise, and disruption of network security functions.
Mitigation Recommendations
No patch or official fix information is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, avoid connecting Firebox devices to untrusted or potentially malicious VPN servers.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hrq5-fh6w-qjmh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-86131"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abc5d3f680226ef6899ba41
Added to database: 09/30/2026, 00:52:15 UTC
Last enriched: 09/30/2026, 01:21:23 UTC
Last updated: 09/30/2026, 01:21:23 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.