Description
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
WatchGuard AP 3.4.8
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-86102 |
|
History
Mon, 28 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system. | |
| Title | WatchGuard AP Command Injection in Internal Management API Allows Command Execution | |
| First Time appeared |
Watchguard
Watchguard watchguard Ap |
|
| Weaknesses | CWE-78 CWE-863 |
|
| CPEs | cpe:2.3:a:watchguard:watchguard_ap:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard watchguard Ap |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-28T16:51:22.163Z
Reserved: 2026-09-04T23:38:48.381Z
Link: CVE-2026-86102
No data.
Status : Received
Published: 2026-09-28T17:17:51.267
Modified: 2026-09-28T17:17:51.267
Link: CVE-2026-86102
No data.
OpenCVE Enrichment
No data.