CVE-2026-86105
Fireware OS Improper Authorization in Access Portal Reverse Proxy
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
| CWE | CWE-176 CWE-22 CWE-285 |
| Vendor | watchguard |
| Product | fireware os |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard fireware os
Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Fireware OS
2026.3 < 2026.3.2 2025.0 < 2026.2.3 12.0 < 12.12.3
WatchGuard / Fireware OS
12.0 < 12.5.21
References
Credits
WatchGuard AI Security Research Laurent GAFFIE , secorizon.com