CVE-2026-86105: Fireware OS Improper Authorization in Access Portal Reverse Proxy
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated to the Access Portal as a low-privileged user. The issue does not describe exploitation by an unauthenticated remote attacker.
What could an attacker gain through successful exploitation?
A low-privileged Access Portal user could access other web applications that they are not authorized to use. Exploitation involves sending a specially crafted request for a different resource that the user is authorized to access.