OS Command Injection in WatchGuard AP Diagnostic CLI
CVE-2026-87969

8.6HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
28 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-87969?

An OS command injection vulnerability exists in the diagnostic CLI of WatchGuard AP devices. This flaw permits an authenticated administrator to execute arbitrary operating system commands by providing specially crafted input. This vulnerability highlights the importance of secure input validation and proper access controls within administrative interfaces. Administrators must remain vigilant and apply necessary patches to prevent exploitation and ensure the integrity of their systems.

Affected Version(s)

WatchGuard AP 1.0 < 3.4.8

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

WatchGuard thanks Carlos Garrido of Pentraze Cybersecurity for working with us to protect our customers
.