DIRAS TAKE
Urgent: this vulnerability lets an unauthenticated actor get an API session simply by reaching the AP on the network; apply the vendor fix (3.4.8) or isolate AP management interfaces immediately.
What is CVE-2026-101891?
An unauthenticated attacker with network access to a WatchGuard AP can obtain a valid API session, allowing access to the device's internal API and potentially perform privileged actions. This is tracked as CVE-2026-101891. The flaw affects WatchGuard AP firmware from 1.0 up to, but not including, 3.4.8; an attacker only needs network access to the AP and does not need valid credentials or user interaction.
Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Which versions of WatchGuard WatchGuard AP are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 1.0 – before 3.4.8 | 3.4.8 |
Is CVE-2026-101891 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-101891
- Upgrade WatchGuard AP firmware to version 3.4.8 or later.
- Restrict network access to AP management and API ports to trusted management networks only.
- Rotate API credentials and any keys or tokens that could be exposed via the AP API.
- Monitor AP logs for suspicious API sessions and follow the vendor's mitigation guidance.
Frequently asked questions
Is CVE-2026-101891 being actively exploited?
There are no public reports of exploitation of CVE-2026-101891 as of 2026-09-30.
Which WatchGuard AP versions are affected by CVE-2026-101891?
WatchGuard AP firmware versions from 1.0 up to, but not including, 3.4.8 are affected; 3.4.8 contains the fix.
Is there a patch for CVE-2026-101891?
Yes. WatchGuard published a fix in firmware version 3.4.8; updating to 3.4.8 or later mitigates the issue.
Does CVE-2026-101891 require authentication?
No. The vulnerability allows an unauthenticated attacker with network access to the AP to obtain a valid API session without credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-101891
- cve.org/CVERecord?id=CVE-2026-101891
- psirt.watchguard.com/CVE-2026-101891
- All WatchGuard CVEs on CVE Radar
- CVEs published in September 2026