CVE-2026-101891 — CVSS 9.3 CRITICAL

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Loading application…