WatchGuard TechnologiesCVE-2026-95676
WatchGuard Technologies AuthPoint Authentication: improper authentication
High7.4CVE-2026-95676 · Published Sep 23, 2026 · updated Sep 24, 2026
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| AuthPoint Authentication Gateway Product | >= 4.2.2, < 7.5.1 | 7.5.1 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | WatchGuard Technologies Dimension: cross-site request forgery | High7.0 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: SQL injection | High8.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.8 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: observable discrepancy | Medium6.3 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: improper access control | Medium6.9 | 2.3.1 |