CVE-2026-86136: Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Devices running WatchGuard Fireware OS are exposed if an attacker has an authenticated low-privileged management account. Read-only and guest administrator accounts are explicitly included.
What access does an attacker need?
The attacker must be able to authenticate to the wgagent management API and submit a specially crafted management API request. The available information does not indicate that unauthenticated exploitation is possible.
What could an attacker do after exploiting this issue?
An attacker can crash the wgagent process, causing a denial of service, and read arbitrary files that are accessible to the wgagent daemon.