๐Ÿ” CVE Alert

CVE-2026-86105

UNKNOWN 0.0

Fireware OS Improper Authorization in Access Portal Reverse Proxy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

CWE CWE-176 CWE-22 CWE-285
Vendor watchguard
Product fireware os
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for watchguard fireware os

Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WatchGuard / Fireware OS
2026.3 < 2026.3.2 2025.0 < 2026.2.3 12.0 < 12.12.3
WatchGuard / Fireware OS
12.0 < 12.5.21

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
psirt.watchguard.com: https://psirt.watchguard.com/CVE-2026-86105

Credits

WatchGuard AI Security Research Laurent GAFFIE , secorizon.com