Skip to content

CVE 2026 101891

psirt.watchguard.com • September 29, 2026

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Weakness Type and Impact #

CWE CWE-284 Improper Access Control

CWE CWE-923 Improper Restriction of Communication Channel to Intended Endpoints

CAPEC CAPEC-115 Authentication Bypass

Exploitation Status #

Discovered internally by WatchGuard finder

View the canonical record on cve.org

Extracted Entities

Attack Types (1)

Domains (1)