CVE-2026-86136
published 2026-09-30CVE-2026-86136: A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user…
PriorityP353high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
0.27%
16.8th percentile
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware | >= 12.12 < 12.12.3 | 12.12.3 |
| watchguard | fireware | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware | >= 2026.3 < 2026.3.2 | 2026.3.2 |
| watchguard | fireware_os | >= 12.0 < 12.12.3 | 12.12.3 |
| watchguard | fireware_os | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware_os | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware_os | >= 2026.0 < 2026.3.2 | 2026.3.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator acco
ghsa_unreviewed·2026-09-30
CVE-2026-86136 [HIGH] CWE-22 A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator acco
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
VulDB
WatchGuard Fireware OS wgagent management daemon session initialization function missing authentication
vuldb·2026-09-30·CVSS 7.1
CVE-2026-86136 [HIGH] WatchGuard Fireware OS wgagent management daemon session initialization function missing authentication
A vulnerability identified as very critical has been detected in WatchGuard Fireware OS. This issue affects the function session initialization function of the component wgagent management daemon. The manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-86136. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-30
Published