Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-86136 |
|
Wed, 30 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | |
| Title | Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-22 CWE-476 CWE-862 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-30T15:28:13.707Z
Reserved: 2026-09-05T03:22:58.693Z
Link: CVE-2026-86136
Updated: 2026-09-30T15:25:42.577Z
Status : Awaiting Analysis
Published: 2026-09-30T00:16:37.213
Modified: 2026-09-30T16:40:50.560
Link: CVE-2026-86136
No data.
OpenCVE Enrichment
Updated: 2026-09-30T08:15:17Z