CVE-2026-91164

CVE-2026-91164 published: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning user's allowed_ip_r...

View full NVD advisory → ← Back to CVE watch