CVE-2026-95676

Summary

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.

Affected Software

VendorProductVersion RangeStatus
WatchGuardAuthPoint Authentication Gateway4.2.2 < 7.5.1affected

Weaknesses

  • CWE-287: CWE-287
  • CWE-636: CWE-636

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References