CVE-2026-86101

Published on September 29, 2026

An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.

Weakness type (CWE)CWE-285, CWE-863

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database