CVE-2026-86105 PUBLISHED

Fireware OS Improper Authorization in Access Portal Reverse Proxy

Assigner: WatchGuard
Reserved: 05.09.2026 Published: 29.09.2026 Updated: 30.09.2026

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 2026.3 to 2026.3.2 (excl.)
  • affected from 2025.0 to 2026.2.3 (excl.)
  • affected from 12.0 to 12.12.3 (excl.)
Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.0 to 12.5.21 (excl.)

Affected Configurations

This vulnerability affects Firebox deployments where the Access Portal is configured with multiple reverse-proxy resources.

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21

Credits

  • WatchGuard AI Security Research finder
  • Laurent GAFFIE , secorizon.com finder

References

Problem Types

  • CWE-176 CWE
  • CWE-22 CWE
  • CWE-285 CWE