Description
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
AuthPoint Authentication Gateway 7.5.1
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-95676 |
|
History
Wed, 23 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply. | |
| Title | AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass | |
| First Time appeared |
Watchguard
Watchguard authpoint Authentication Gateway |
|
| Weaknesses | CWE-287 CWE-636 |
|
| CPEs | cpe:2.3:a:watchguard:authpoint_authentication_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard authpoint Authentication Gateway |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-23T12:52:04.902Z
Reserved: 2026-09-22T13:47:30.359Z
Link: CVE-2026-95676
No data.
Status : Received
Published: 2026-09-23T13:17:32.143
Modified: 2026-09-23T13:17:32.143
Link: CVE-2026-95676
No data.
OpenCVE Enrichment
No data.