CVE-2026-90441
published 2026-09-30CVE-2026-90441: A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user…
PriorityP352high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
0.21%
9.8th percentile
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware | >= 12.12 < 12.12.3 | 12.12.3 |
| watchguard | fireware | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware | >= 2026.3 < 2026.3.2 | 2026.3.2 |
| watchguard | fireware_os | >= 12.0 < 12.12.3 | 12.12.3 |
| watchguard | fireware_os | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware_os | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware_os | >= 2026.3 < 2026.3.2 | 2026.3.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WatchGuard Fireware OS wgagent management daemon session initialization improper authorization
vuldb·2026-09-30·CVSS 7.1
CVE-2026-90441 [HIGH] WatchGuard Fireware OS wgagent management daemon session initialization improper authorization
A vulnerability marked as critical has been reported in WatchGuard Fireware OS. The affected element is the function session initialization of the component wgagent management daemon. This manipulation causes improper authorization.
This vulnerability is registered as CVE-2026-90441. Remote exploitation of the attack is possible. No exploit is available.
GHSA
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator acco
ghsa_unreviewed·2026-09-30
CVE-2026-90441 [HIGH] CWE-200 A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator acco
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-30
Published