An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
Advisories
No advisories yet.
Fixes
Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-86105 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access. | |
| Title | Fireware OS Improper Authorization in Access Portal Reverse Proxy | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-176 CWE-22 CWE-285 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.554Z
Reserved: 2026-09-05T00:16:03.449Z
Link: CVE-2026-86105
No data.
Status : Received
Published: 2026-09-30T00:16:36.550
Modified: 2026-09-30T00:16:36.550
Link: CVE-2026-86105
No data.
OpenCVE Enrichment
Updated: 2026-09-30T01:15:04Z