CVE-2026-90441: Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
Affected Software
Event History
Frequently Asked Questions
Which accounts can exploit this issue?
An authenticated low-privileged user can exploit it, including users with read-only or guest administrator accounts. No higher-privileged administrative role is required.
What access does an attacker need to trigger the vulnerability?
The attacker needs access to the wgagent management API and valid credentials for a low-privileged account. Exploitation involves sending a specially crafted management API request during session initialization.
What is the operational and data exposure impact?
A successful request can crash the wgagent process, causing a denial of service. It can also allow reading arbitrary files that are accessible to the wgagent daemon.