CVE-2026-86102

WatchGuard AP Command Injection in Internal Management API Allows Command Execution

Critical 9.3 CVSS v4.0 › Published 2026-09-28Updated 2026-09-28

Summary #

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

Product status #

ProductAffectedNot affected
WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8

Weakness Type and Impact #

  • CWECWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CWECWE-863Incorrect Authorization
  • CAPECCAPEC-88OS Command Injection

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard AP 3.4.8

References #

    Credits #

    • Yukusawa18finder