Description
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
No analysis available yet.
Remediation
Vendor Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-90441 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | |
| Title | Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-200 CWE-400 CWE-862 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.593Z
Reserved: 2026-09-11T20:56:13.208Z
Link: CVE-2026-90441
No data.
Status : Received
Published: 2026-09-30T00:16:37.363
Modified: 2026-09-30T00:16:37.363
Link: CVE-2026-90441
No data.
OpenCVE Enrichment
Updated: 2026-09-30T01:15:04Z