CVE-2026-101891 Details
Description
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
A vulnerability allowing improper access control has been identified in an internal API service on WatchGuard Access Points, versions 1.0 through 3.4.8. This vulnerability allows an unauthenticated attacker with network access to the access point to obtain a valid API session.
Users can upgrade to WatchGuard AP version 3.4.8 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.watchguard.com/CVE-2026-101891 | WatchGuard Technologies, Inc. | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | WatchGuard Technologies, Inc. |
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | WatchGuard Technologies, Inc. |
Affected Products
| Product | Versions |
|---|---|
| WatchGuard AP | >= 1.0, < 3.4.8 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | WatchGuard Technologies, Inc. |
Volerion