Authentication Bypass in WatchGuard AuthPoint Gateway
CVE-2026-95676

7.4HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
23 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-95676?

A vulnerability exists within the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication, which may allow remote attackers to bypass single-factor password verification under specific operating conditions that deviate from default settings. While additional authentication measures remain in place, the flaw poses significant security concerns as it could be exploited by unauthorized individuals to gain access to protected resources.

Affected Version(s)

AuthPoint Authentication Gateway 4.2.2 < 7.5.1

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered internally by WatchGuard
.