CVE-2026-86105
published 2026-09-30CVE-2026-86105: An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other…
PriorityP345high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.36%
27.3th percentile
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware | >= 12.12 < 12.12.3 | 12.12.3 |
| watchguard | fireware | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware | >= 2026.3 < 2026.3.2 | 2026.3.2 |
| watchguard | fireware_os | >= 12.0 < 12.12.3 | 12.12.3 |
| watchguard | fireware_os | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware_os | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware_os | >= 2026.3 < 2026.3.2 | 2026.3.2 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WatchGuard Fireware OS Access Portal improper authorization
vuldb·2026-09-30·CVSS 6.0
CVE-2026-86105 [MEDIUM] WatchGuard Fireware OS Access Portal improper authorization
A vulnerability was found in WatchGuard Fireware OS and classified as critical. Affected is an unknown function of the component Access Portal. The manipulation results in improper authorization.
This vulnerability was named CVE-2026-86105. The attack may be performed from remote. There is no available exploit.
GHSA
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized
ghsa_unreviewed·2026-09-30
CVE-2026-86105 [MEDIUM] CWE-22 An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-30
Published