Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-101891: WatchGuard Access Point lets anyone on network get API session
CVE-2026-101891 · published 11 days ago
Summary
The internal API on WatchGuard Access Points can be reached without any login, so anyone who can reach the device on the network can obtain a valid API session. This could let an attacker control the access point or view its settings. Apply the latest software update from WatchGuard and limit network access to the device to trusted hosts.
What to do
- Update watchguard watchguard ap to version 3.4.8 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| watchguard | watchguard ap | < 3.4.8 |
Original advisory text
WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-284Improper Access Control
CWE-923Improper Restriction of Communication Channel to Intended Endpoints
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta