CVE-2026-95676
Received Received - Intake

Authentication Bypass in WatchGuard AuthPoint Gateway

Vulnerability report for CVE-2026-95676, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WatchGuard Technologies, Inc.

Description

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
watchguard authpoint_authentication_gateway 7.5.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-636 When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing or improper authentication issue in WatchGuard AuthPoint Gateway's LDAP Sync feature. It allows a remote attacker to bypass single-factor password verification when specific non-default settings are used. The default configuration is not affected. Additional authentication factors, if enabled, remain functional.

Detection Guidance

To detect this vulnerability, check the version of your WatchGuard AuthPoint Authentication Gateway. If it is below 7.5.1, the system may be affected. Verify if LDAP Sync is enabled and review authentication logs for any unusual bypass attempts during non-default configurations.

Impact Analysis

An attacker could exploit this to bypass password verification under certain conditions, potentially gaining unauthorized access to systems relying on the LDAP Sync feature. However, exploitation requires non-default configurations and does not affect default setups. Additional authentication factors mitigate the risk.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by allowing unauthorized access to systems through bypassed authentication. However, the issue only affects non-default configurations and does not impact default setups where additional authentication factors are enabled.

Mitigation Strategies

Update the WatchGuard AuthPoint Authentication Gateway to version 7.5.1 or later to resolve the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95676. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart