WatchGuard TechnologiesCVE-2026-101891
WatchGuard AP: improper access control
Critical9.3CVE-2026-101891 · Published Sep 28, 2026
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WatchGuard AP Product | >= 1.0, < 3.4.8 | 3.4.8 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | WatchGuard Technologies Fireware OS: integer overflow | High8.2 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: resource exhaustion | High7.1 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: path traversal | High8.2 | 12.5.21+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: unsafe deserialization | High7.5 | 2026.3.2+3 more |
| Sep 28 | WatchGuard AP: command injection | Critical9.3 | 3.4.8 |
| Sep 28 | WatchGuard AP: command injection | High8.6 | 3.4.8 |