• PATCH AVAILABLE

CVE-2026-101891: improper access control in WatchGuard WatchGuard AP

An unauthenticated attacker with network access to a WatchGuard AP can obtain a valid API session, allowing access to the device's internal API and potentially perform privileged actions. This is tracked as CVE-2026-101891. The flaw affects WatchGuard AP firmware from 1.0 up to, but not including, 3.4.8; an attacker only needs network access to the AP and does not need valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 4.0
9.3CRITICAL
EPSS
0.00273
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this vulnerability lets an unauthenticated actor get an API session simply by reaching the AP on the network; apply the vendor fix (3.4.8) or isolate AP management interfaces immediately.

What is CVE-2026-101891?

An unauthenticated attacker with network access to a WatchGuard AP can obtain a valid API session, allowing access to the device's internal API and potentially perform privileged actions. This is tracked as CVE-2026-101891. The flaw affects WatchGuard AP firmware from 1.0 up to, but not including, 3.4.8; an attacker only needs network access to the AP and does not need valid credentials or user interaction.

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of WatchGuard WatchGuard AP are affected?

BRANCHAFFECTEDFIXED
3.x1.0 – before 3.4.83.4.8

Is CVE-2026-101891 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-101891

  1. Upgrade WatchGuard AP firmware to version 3.4.8 or later.
  2. Restrict network access to AP management and API ports to trusted management networks only.
  3. Rotate API credentials and any keys or tokens that could be exposed via the AP API.
  4. Monitor AP logs for suspicious API sessions and follow the vendor's mitigation guidance.

Frequently asked questions

Is CVE-2026-101891 being actively exploited?

There are no public reports of exploitation of CVE-2026-101891 as of 2026-09-30.

Which WatchGuard AP versions are affected by CVE-2026-101891?

WatchGuard AP firmware versions from 1.0 up to, but not including, 3.4.8 are affected; 3.4.8 contains the fix.

Is there a patch for CVE-2026-101891?

Yes. WatchGuard published a fix in firmware version 3.4.8; updating to 3.4.8 or later mitigates the issue.

Does CVE-2026-101891 require authentication?

No. The vulnerability allows an unauthenticated attacker with network access to the AP to obtain a valid API session without credentials.

References