Vulnerability in Warpgate SSH and HTTPS Bastion Host for Linux
CVE-2026-91166

5.7MEDIUM

Key Information:

Vendor

Warp-tech

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-91166?

A vulnerability exists in Warpgate versions 0.25.0 through 0.27.6 that improperly handles the browser SSH path in the management interface. This issue occurs when the system handles unknown host keys without verifying the hop identity. As a result, in Prompt and AutoAccept modes, a malicious jump host key can be accepted for the target address, potentially allowing an attacker to intercept user traffic or issue fraudulent certificates during certificate authentication. The problem is resolved in version 0.27.6, which adds necessary safeguards to ensure proper verification of each hop.

Affected Version(s)

warpgate >= 0.25.0, < 0.27.6

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.