CVE-2026-86136 PUBLISHED

Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A

Assigner: WatchGuard
Reserved: 05.09.2026 Published: 29.09.2026 Updated: 30.09.2026

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 2026.0 to 2026.3.2 (excl.)
  • affected from 2025.0 to 2026.2.3 (excl.)
  • affected from 12.0 to 12.12.3 (excl.)
Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.0 to 12.5.21 (excl.)

Affected Configurations

To exploit this vulnerability, an attacker requires network access to a management interface on the Firebox.

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21

Credits

  • WatchGuard AI Security Research finder

References

Problem Types

  • CWE-22 CWE
  • CWE-476 CWE
  • CWE-862 CWE