CVE-2026-95676: AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass
Published Sep 23, 2026
·Updated
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
Affected Software
1 affected component
WatchGuard AuthPoint Gateway
Event History
Sep 23, 2026
CVE Published
via MITRE·12:52 PM
Data Sourced
via MITRE·12:52 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Are default AuthPoint Gateway deployments affected?
The vulnerability is described as occurring under non-default operating conditions, so it is not indicated to affect default configurations.
2
What access does an attacker need to exploit this issue?
A remote attacker can exploit the issue. The available information does not specify any required prior access or privileges.
3
Does exploiting this vulnerability bypass all AuthPoint authentication requirements?
No. The issue bypasses single-factor password verification in LDAP Sync first-factor authentication, but additional authentication factors still apply.