CVE-2026-86136
Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
| CWE | CWE-22 CWE-476 CWE-862 |
| Vendor | watchguard |
| Product | fireware os |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard fireware os
Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Fireware OS
2026.0 < 2026.3.2 2025.0 < 2026.2.3 12.0 < 12.12.3
WatchGuard / Fireware OS
12.0 < 12.5.21
References
Credits
WatchGuard AI Security Research