OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-86105

HIGH · CVSS 7.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy enables low-privileged authenticated users to access unauthorized web applications by crafting specific requests. This could lead to unauthorized data exposure or manipulation, impacting the confidentiality and integrity of sensitive information. Organizations using Fireware OS should prioritize addressing this vulnerability to safeguard their web applications from potential exploitation.

CVE
CVE-2026-86105
Severity
HIGH
CVSS
7.1
EPSS
0.31%

Original NVD Description

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

Related CVEs

Other vulnerabilities affecting the same vendor(s)