CVE-2026-101891 PUBLISHED

WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access

Assigner: WatchGuard
Reserved: 28.09.2026 Published: 28.09.2026 Updated: 28.09.2026

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor WatchGuard
Product WatchGuard AP
Versions Default: unaffected
  • affected from 1.0 to 3.4.8 (excl.)

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

WatchGuard AP 3.4.8

Credits

  • Discovered internally by WatchGuard finder

References

Problem Types

  • CWE-284 CWE
  • CWE-923 CWE