---
id: CVE-2026-86102
title: >-
  An OS command injection vulnerability in the WatchGuard AP internal API
  service allows an attacker with network access to the AP to execute arbitrary
  shell commands on the underlying operating system.
summary: >-
  An OS command injection vulnerability in the WatchGuard AP internal API
  service allows an attacker with network access to the AP to execute arbitrary
  shell commands on the underlying operating system.
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
  - CWE-863
vendor: WatchGuard
product: WatchGuard AP
affected:
  - ap >= 1.0 < 3.4.8
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T18:17:25.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86102'
references:
  - url: 'https://psirt.watchguard.com/CVE-2026-86102'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-28T17:19:49.821749Z'
cvssSource: cna
ingestedAt: '2026-09-28T17:16:27.807Z'
---

## Overview

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
