CVE-2026-86102 PUBLISHED

WatchGuard AP Command Injection in Internal Management API Allows Command Execution

Assigner: WatchGuard
Reserved: 04.09.2026 Published: 28.09.2026 Updated: 28.09.2026

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor WatchGuard
Product WatchGuard AP
Versions Default: unaffected
  • affected from 1.0 to 3.4.8 (excl.)

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

WatchGuard AP 3.4.8

Credits

  • Yukusawa18 finder

References

Problem Types

  • CWE-78 CWE
  • CWE-863 CWE