CVE-2026-95676

AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass

High 7.4 CVSS v4.0 › Published 2026-09-23Updated 2026-09-23

Summary #

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.

Product status #

ProductAffectedNot affected
AuthPoint Authentication Gateway>= 4.2.2, < 7.5.1>= 7.5.1

Weakness Type and Impact #

  • CWECWE-287Improper Authentication
  • CWECWE-636Not Failing Securely ('Failing Open')
  • CAPECCAPEC-115Authentication Bypass

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

AuthPoint Authentication Gateway 7.5.1

References #

    Credits #

    • Discovered internally by WatchGuardfinder