{"id":"CVE-2026-86105","published":"2026-09-30T00:16:36.550","lastModified":"2026-09-30T00:16:36.550","description":"An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-22","CWE-176","CWE-285"],"vendors":[],"products":[],"references":[{"url":"https://psirt.watchguard.com/CVE-2026-86105","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}