CVE-2026-95676#
AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass
Summary #
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| AuthPoint Authentication Gateway | >= 4.2.2, < 7.5.1 | >= 7.5.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
AuthPoint Authentication Gateway 7.5.1
References #
Credits #
- Discovered internally by WatchGuardfinder