Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not require AdminPermission
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58491 | 9.3 CRITICAL | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter |
| CVE-2026-63330 | 7.7 HIGH | Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authen |
| CVE-2026-91166 | 5.7 MEDIUM | Warpgate: Web SSH stores a jump host's key against the target's address, so it validates a |
| CVE-2026-63329 | 4.9 MEDIUM | Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Sp |
| CVE-2026-91164 | 4.3 MEDIUM | Warpgate: API tokens bypass the user's allowed_ip_ranges restriction |
| CVE-2026-91165 | 2.4 LOW | Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error value |
No comments yet