CVE-2026-101891

WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access

Critical 9.3 CVSS v4.0 › Published 2026-09-28Updated 2026-09-28

Summary #

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Product status #

ProductAffectedNot affected
WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8

Weakness Type and Impact #

  • CWECWE-284Improper Access Control
  • CWECWE-923Improper Restriction of Communication Channel to Intended Endpoints
  • CAPECCAPEC-115Authentication Bypass

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard AP 3.4.8

References #

    Credits #

    • Discovered internally by WatchGuardfinder