CVE-2026-91167Medium· 6.0▾ SunlitWarpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not require AdminPermission::AccessRolesAssign. A limited administrator with any permission can update expires_at on an existing UserRoleAssignment and clear revoked_at, extending an expiring grant or reinstating a revoked grant. The endpoint cannot create a role assignment that never existed because it returns not found without a matching user and role pair. This issue is fixed in version 0.28.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63330High· 7.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-91166Medium· 5.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-91164Medium· 4.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-91165Low· 2.4Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-63329Medium· 4.9Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-58491Critical· 9.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux