CVE-2026-86101
Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.
| CWE | CWE-285 CWE-863 |
| Vendor | watchguard |
| Product | fireware os |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard fireware os
Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Fireware OS
2026.3 < 2026.3.2 2025.0 < 2026.2.3 12.0 < 12.12.3
WatchGuard / Fireware OS
12.0 < 12.5.21
References
Credits
Laurent GAFFIE , secorizon.com