CVE-2026-87969

WatchGuard AP Authenticated Command Injection in Diagnostic CLI

High 8.6 CVSS v4.0 › Published 2026-09-28Updated 2026-09-28

Summary #

An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.

Product status #

ProductAffectedNot affected
WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8

Weakness Type and Impact #

  • CWECWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CAPECCAPEC-88OS Command Injection

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard AP 3.4.8

References #

    Credits #

    • WatchGuard thanks Carlos Garrido of Pentraze Cybersecurity for working with us to protect our customersfinder