Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

10/7/2026 • Security

WatchGuard SAML Flaw: Logged In to the Portal, Let In to the VPN

WatchGuard has patched CVE-2026-86101, an authorisation bypass in Fireware's SAML login that let a user who was only allowed the Access Portal open a Mobile VPN with SSL session instead. Fixed in Fireware 12.12.3, 2026.2.3, 2026.3.2 and 12.5.21; not exploited.

On 29 September 2026 WatchGuard published fourteen security advisories for Fireware OS, the operating system on its Firebox firewalls, and one of them describes a failure that has nothing to do with buffer overflows or crafted packets. CVE-2026-86101 is an authorisation bug in the way a Firebox handles SAML single sign-on. A user who has legitimately signed in through your identity provider, but who was only ever meant to use the Access Portal, can send a specially crafted request and come away with a Mobile VPN with SSL session instead. The firewall checked who they were. It didn't properly check what they were allowed to have. Nobody is known to be exploiting it, the fix shipped the same day as the advisory, and we mentioned it in passing in last week's post on the DHCP flaw. It deserves a closer look of its own, because the mistake it illustrates is one small businesses make in their own access setups all the time.

What happened, in plain English

Two WatchGuard features sit behind this story. The Access Portal is a clientless portal on the Firebox: staff open a web page, sign in, and see links to the web applications, remote desktops and SSH hosts the administrator has chosen to publish to them, and nothing else. It is the tidy way to give a contractor one application without giving them your network. Mobile VPN with SSL is the other end of the spectrum: a VPN client that puts the whole device onto the networks behind the firewall, with whatever your VPN policies allow.

Both can authenticate users through SAML, the single sign-on standard that lets the Firebox hand the login over to an identity provider such as Okta or OneLogin. The identity provider confirms who the user is and passes back their group memberships (the Firebox reads a group attribute called memberOf by default), and the Firebox is meant to use those groups to decide what the user may reach. SAML for the Access Portal has been in Fireware since version 12.1; SAML for the Mobile VPN with SSL client arrived in Fireware 12.11.

CVE-2026-86101 lives in the gap between those two decisions. WatchGuard's advisory says the flaw "allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request." The release notes for the fix put it even more plainly: the update "resolves an authorization bypass vulnerability that allowed an authenticated SAML user to establish an unauthorized Mobile VPN with SSL session."

The nuances, because getting them right is the whole job here:

  • It needs a real login first. The CVSS v4.0 vector is AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N. PR:L means the attacker must already hold a valid account at your identity provider that is permitted to use the Access Portal. AT:P means the deployment has to be set up a particular way, in practice SAML in use on the Firebox. This is not an anonymous attacker on the internet. It is a limited insider, or a stolen limited identity, being escalated.
  • The impact lands on what's behind the firewall. The vector records high confidentiality impact on the Firebox and high confidentiality and integrity impact on subsequent systems. A VPN session is a path onto your LAN, and that is what the score is pricing. WatchGuard rates it 7.2 High.
  • It is not being exploited. WatchGuard says it is "not aware of any exploitation of this vulnerability in the wild." The CVE is not on CISA's Known Exploited Vulnerabilities list as of the 4 October 2026 catalogue, and CISA's own assessment attached to the NVD record marks exploitation as "none" and the flaw as not automatable. It was reported by researcher Laurent Gaffié of Secorizon, so this is coordinated disclosure, not an incident write-up.
  • The score is the vendor's. As at 6 October 2026 the NVD record is still "Undergoing Analysis," so 7.2 is WatchGuard's number, not an independent reassessment.
  • Affected versions are wide. Fireware OS 12.0 up to but not including 12.12.3; 2025.0 up to but not including 2026.2.3; 2026.3 up to but not including 2026.3.2; and on the Firebox T15 and T35, 12.0 up to but not including 12.5.21. The fixes are 12.12.3, 2026.2.3, 2026.3.2 and 12.5.21, all released on 29 September 2026.
  • One wrinkle for the T15 and T35. The advisory lists 12.5.21 as the fix for those models, but the 12.5.21 release notes name eleven resolved CVEs and this is not among them. Whether that is a gap in the notes or caution in the advisory, the action is the same: put a T15 or T35 on 12.5.21 regardless, because it needs the other eleven fixes anyway.
  • It travels with company. The same 12.12.3 release also resolves path-authorisation and directory-traversal flaws in the Access Portal reverse proxy (CVE-2026-86105) and an untrusted-data deserialisation bug in the SAML daemon (CVE-2026-13046). One firmware update covers the lot.

Why it matters: logged in is not the same as allowed

Authentication asks "who are you?" Authorisation asks "and what are you allowed to do?" Single sign-on is very good at the first question, and that is exactly why it tempts everyone to assume the second one is handled. In this case the identity provider did its job: the user was real, the password and second factor were good, the group list came back correct. The Firebox then failed to hold the line between "may use the portal" and "may open a VPN."

That matters more for a small business than the score suggests, because of who the Access Portal is for. It is the feature you reach for with the people you trust least: the external bookkeeper who needs one web application, the contractor who needs one remote desktop, the former staff member kept on for a handover. Those are accounts whose compromise you have already priced as low-impact, which is why they get the portal and not the VPN. This bug would have quietly raised the price. A phished contractor login stops being a nuisance confined to one app and becomes a VPN session on your network.

It is the same shape as flaws we have covered elsewhere in this series. SonicWall's email gateway let a login become root, and Cisco ISE skipped the login entirely. Authentication gets the engineering attention. Authorisation gets the bugs.

The honest bit

This is our fourth WatchGuard post in six weeks, after the August VPN flaw, the access points, the AuthPoint Gateway and last week's DHCP flaw. That run says less about WatchGuard than it does about a vendor with an active researcher community and a security team that publishes everything it fixes. This one was researcher-reported, fixed before the advisory went up, named in the release notes and honest about exploitation. No vendor is immune, including the ones we like, and this is what handling it properly looks like.

Two details worth knowing before you decide whether this applies to you. SAML on the Access Portal covers web applications only; RDP and SSH sessions through the portal use other authentication. And a Firebox supports one identity provider at a time, so if SAML is on, it is on for everything you have ticked. Where a platform choice genuinely helps is in how quickly the fix reaches the box: WatchGuard Cloud can push 12.12.3 to any Firebox running 12.5.2 or later from the console, and cloud-managed firewalls in general take their updates on a schedule you set rather than when someone remembers. We have written about why that matters.

What we'd suggest you actually do

  1. Check the Fireware version on every Firebox and upgrade this week. Move to 12.12.3, 2026.2.3 or 2026.3.2 depending on your branch, or 12.5.21 on a T15 or T35. Back up the configuration first, and expect a reboot.
  2. Work out whether SAML is actually on. In Fireware 12.11 and later it lives under Authentication > Servers; on older releases it is under the Access Portal settings. If SAML is not enabled for anything, this particular flaw does not reach you, but the other thirteen advisories still do.
  3. List who can use the portal and who should hold a VPN. Write down the identity-provider groups mapped to each. Contractors, suppliers and former staff belong in the first list and almost never in the second.
  4. Look back through your Mobile VPN with SSL logs. A VPN session from an account that was never issued the client is the signature of this bug. If you find one, treat it as an incident, not a curiosity.
  5. Put multi-factor authentication at the identity provider. With SAML, the identity provider's second factor is the one that counts. A stolen password should not be enough to reach the portal, let alone escalate from it.
  6. Limit what a VPN session can reach. The policies for your VPN user group should name the servers people need, not "Any." Least privilege on the VPN is what turns an authorisation bug from a breach into a shrug.
  7. Subscribe to WatchGuard's advisory feed. psirt.watchguard.com publishes RSS. Fourteen advisories should land in your inbox the day they are published.

The friendly takeaway

This is not a five-alarm fire. It needs a valid login, nobody is known to be exploiting it, and the fix shipped the same day it was announced. What earns it your ten minutes is the lesson underneath: being signed in is not the same as being allowed in, and on a firewall that distinction is the whole product. Patch this week, and take a moment to confirm that the people who can only use your portal really can only use your portal.

As always, this is part of us keeping watch so you don't have to. If you would like a second pair of eyes over your Firebox sign-on setup, who maps to what, what the VPN can reach, and whether the logs show anything odd, get in touch. No obligation, no hard sell.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.