{"id":"CVE-2026-101891","published":"2026-09-28T17:17:48.677","lastModified":"2026-09-28T20:51:05.473","description":"An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-284","CWE-923"],"vendors":[],"products":[],"references":[{"url":"https://psirt.watchguard.com/CVE-2026-101891","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}