CVE-2026-87969: WatchGuard AP Authenticated Command Injection in Diagnostic CLI
Published Sep 28, 2026
·Updated
An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.
Affected Software
1 affected component
WatchGuard AP diagnostic CLI
Event History
Sep 28, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
Exploitation requires authenticated administrator access to the WatchGuard AP diagnostic CLI. A successful attacker can supply crafted input to execute arbitrary operating system commands.