CVE-2026-86101: Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access
An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
Which users can exploit this issue?
A remote user who can authenticate through SAML and is authorized only for the Access Portal can exploit it. The issue can grant that user Mobile VPN with SSL access beyond their intended authorization.
What access does an attacker need before exploitation?
The attacker must already be an authenticated SAML user with Access Portal access. Exploitation requires sending a specially crafted request.