VDB

CVE-2026-86105

CVE-2026-86105 PUBLISHED CVSS 5.3 MEDIUM

Reported by WatchGuard · Published September 29, 2026

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

Risk Scores

CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
WatchGuardFireware OS2026.3, 2025.0, 12.0
WatchGuardFireware OS12.0
WatchGuardFireware OS2026.3, 2025.0, 12.0
watchguardfireware_os12.0, 2026.3, 2025.0

Timeline

  • Sep 29, 2026 CVE Published
  • Sep 30, 2026 EPSS Score
  • Oct 3, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
  • Oct 6, 2026 CVE Updated

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›