CVE-2026-95676 PUBLISHED

AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass

Assigner: WatchGuard
Reserved: 22.09.2026 Published: 23.09.2026 Updated: 23.09.2026

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.4

Product Status

Vendor WatchGuard
Product AuthPoint Authentication Gateway
Versions Default: unaffected
  • affected from 4.2.2 to 7.5.1 (excl.)

Affected Configurations

This vulnerability affects deployments that are configured to sync AuthPoint users from an LDAP source.

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

AuthPoint Authentication Gateway 7.5.1

Credits

  • Discovered internally by WatchGuard finder

References

Problem Types

  • CWE-287 CWE
  • CWE-636 CWE