CVE-2026-101891: WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
Published Sep 28, 2026
·Updated
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
Affected Software
1 affected component
WatchGuard Access Points
Event History
Sep 28, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker who has network access to a vulnerable WatchGuard Access Point can exploit the internal API service to obtain a valid API session.
2
Does exploitation require valid credentials?
No. The vulnerability allows an unauthenticated attacker to obtain a valid API session.