CVE-2026-44347 Details
Description
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user into logging into the attacker's account, possibly convincing them to perform sensitive actions on the attacker's account (such as writing sensitive data to the attacker's SSH target, or logging into an HTTP target that the attacker set up). This vulnerability is fixed in 0.23.3.
A vulnerability in Warpgate prior to version 0.23.3 allows for cross-site request forgery (CSRF) attacks in the single sign-on (SSO) flow. The issue arises because the SSO flow does not validate the 'state' parameter, enabling an attacker to trick a user into logging into the attacker's account. This could lead to the user unintentionally performing sensitive actions on behalf of the attacker, such as transmitting confidential information to the attacker's SSH target or accessing an HTTP target set up by the attacker.
Users can upgrade to Warpgate version 0.23.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warp-tech/warpgate/security/advisories/GHSA-rj86-hm3r-c275 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/warp-tech/warpgate/security/advisories/GHSA-rj86-hm3r-c275 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| warpgate project warpgate | 0.23.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |