CVE-2026-101891
WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
| CWE | CWE-284 CWE-923 |
| Vendor | watchguard |
| Product | watchguard ap |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard watchguard ap
Be the first to know when new unknown vulnerabilities affecting watchguard watchguard ap are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / WatchGuard AP
1.0 < 3.4.8
References
Credits
Discovered internally by WatchGuard