Improper Authentication in Warpgate SSH Bastion Host by WarpTech
CVE-2026-91167
6MEDIUM
What is CVE-2026-91167?
Warpgate, an open-source SSH, HTTPS, and MySQL bastion host for Linux, has a vulnerability that allows limited administrators to manipulate user role assignments without proper permissions. Specifically, the API endpoint responsible for updating user roles can be accessed by an administrator lacking the necessary authorization, enabling them to extend expiring grants or reinstate revoked privileges. This flaw highlights a significant security risk in user role management, where inappropriate access can lead to unauthorized permissions on user accounts. The issue is resolved in version 0.28.4.
Affected Version(s)
warpgate < 0.28.4
