Contact Zero

CVE-2026-86105

watchguard fireware

score 0MEDIUM 6

Summary

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

Published 2026-09-30 · first seen here 2026-10-10

Hunt & detect

Threat hunt brief, Sigma rule and Splunk / Sentinel / CrowdStrike queries are not available for this item yet.

References