CVE-2026-101891
CRITICAL
9,3
Source: 5d1c2695-1a31-4499-88ae-e847036fd7e3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
284
Improper Access Control
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Varies By Context
Applicable Platforms
Technologies:
Not Technology-Specific, ICS/OT, Web Based
923
Improper Restriction of Communication Channel to Intended Endpoints
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, Web Server
https://psirt.watchguard.com/CVE-2026-101891