{"id":"CVE-2026-95676","title":"A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions","summary":"A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Ad…","severity":"high","cvss":7.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-287","CWE-636"],"vendor":"WatchGuard","product":"AuthPoint Authentication Gateway","affected":["authpoint_authentication_gateway >= 4.2.2 < 7.5.1"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T16:16:48.870","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95676","references":[{"url":"https://psirt.watchguard.com/CVE-2026-95676","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T15:24:44.392517Z"},"cvssSource":"cna","ingestedAt":"2026-09-23T13:24:43.400Z","slug":"CVE-2026-95676","body":"## Overview\n\nA missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}