PT-2026-96222 · Warpgate · Warpgate

CVE-2026-91164

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Warpgate versions 0.23.0 through 0.27.2
Description HTTP API token authentication fails to enforce the allowed ip ranges of the owning user against the trusted client address during the resolution of ConfigProvider::validate api token into RequestAuthorization::UserToken within the warpgate-protocol-http/src/common.rs file. This allows an attacker with a leaked, phished, or exfiltrated X-Warpgate-Token to authenticate from a prohibited network location. This issue does not affect deployments without configured allowed ip ranges, nor does it impact HTTP target proxying or paths for SSH, MySQL, PostgreSQL, RDP, VNC, and Kubernetes.
Recommendations Update to version 0.27.3.

Exploit

Fix

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91164
GHSA-QMR2-WP96-H9FF

Affected Products

Warpgate