Threat intelligence dashboard
CVE-2026-101891critical

WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Risk score

9.3

CVSS 4.0

Vendor
WatchGuard
Product
WatchGuard AP
CWE
CWE-284, CWE-923
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

WatchGuard AP

WatchGuard

Version / rangeStatusType
1.0 to before 3.4.8affectedsemver

Technical metrics

9.3

CVSS 4.0

Severity
critical
Source
WatchGuard
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N