important · Edge / privilege
A portal-only WatchGuard SAML identity can enter the SSL VPN.
Affects
WatchGuard Fireware OS on Firebox network-security appliances providing Access Portal and Mobile VPN with SSL services.
The caller still needs valid SAML credentials, but those credentials may be assigned only to the Access Portal.
Detail and 3 sources
A crafted login request selects Mobile VPN with SSL without the authorization check for that function.
WatchGuard lists fixed release ranges.
Sources
ResearchWatchGuard Security AdvisoriesResearchWatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถูกสั่งดำเนินการคำสั่งด้วยสิทธิ์ Root - Thailand Computer Emergency Response Team (ThaiCERT)SecondaryCVE-2026-86101 — Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access