Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-101891: WatchGuard Access Point lets anyone on network get API session

CVE-2026-101891 · published 11 days ago
Summary

The internal API on WatchGuard Access Points can be reached without any login, so anyone who can reach the device on the network can obtain a valid API session. This could let an attacker control the access point or view its settings. Apply the latest software update from WatchGuard and limit network access to the device to trusted hosts.

What to do
  • Update watchguard watchguard ap to version 3.4.8 or later.
Affected software
VendorProductAffected versions
watchguard watchguard ap < 3.4.8
Original advisory text
WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-284Improper Access Control
CWE-923Improper Restriction of Communication Channel to Intended Endpoints
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-101891 · MITRE
Track software like this
Free during beta