CVE-2026-101891

Summary

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Affected Software

VendorProductVersion RangeStatus
WatchGuardWatchGuard AP1.0 < 3.4.8affected

Weaknesses

  • CWE-284: CWE-284
  • CWE-923: CWE-923

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References