CVE 2026 101891
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
Weakness Type and Impact #
CWE CWE-284 Improper Access Control
CWE CWE-923 Improper Restriction of Communication Channel to Intended Endpoints
CAPEC CAPEC-115 Authentication Bypass
Exploitation Status #
Discovered internally by WatchGuard finder
View the canonical record on cve.org
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
