Token Authentication Flaw in Warpgate SSH and HTTPS Bastion Host
CVE-2026-91164
4.3MEDIUM
What is CVE-2026-91164?
A vulnerability in the Warpgate SSH and HTTPS bastion host affects versions 0.23.0 to 0.27.3, allowing unauthorized use of HTTP API tokens. When a token is used from an unapproved network location, it bypasses checks that enforce user-specific IP ranges. Although this weakness affects configurations that do not employ allowed_ip_ranges, deployments with secure configurations remain safe. The issue was rectified in version 0.27.3, highlighting the need for regular updates and vigilance in API security management.
Affected Version(s)
warpgate >= 0.23.0, < 0.27.3
