{"id":"CVE-2026-91166","published":"2026-09-21T19:17:15.383","lastModified":"2026-09-21T19:17:15.383","description":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host and ssh_options.port for the final target to KnownHosts::trust. In Prompt and AutoAccept modes, a jump host key can therefore be stored for the target address. A machine later presenting the jump host key at the target address can be accepted as the target, allowing interception of user traffic and a newly issued certificate when certificate authentication is used. The native SSH path is unaffected because it tracks each hop separately. This issue is fixed in version 0.27.6.","cvssScore":5.7,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N","cwes":["CWE-297","CWE-923"],"vendors":[],"products":[],"references":[{"url":"https://github.com/warp-tech/warpgate/commit/fb66ff74f979c22054f4d348cc0d9065cc67e5d3","tags":[]},{"url":"https://github.com/warp-tech/warpgate/releases/tag/v0.27.6","tags":[]},{"url":"https://github.com/warp-tech/warpgate/security/advisories/GHSA-w9jj-vpw3-5r8f","tags":[]}],"exploitRefs":[{"url":"https://github.com/warp-tech/warpgate/commit/fb66ff74f979c22054f4d348cc0d9065cc67e5d3","tags":[]},{"url":"https://github.com/warp-tech/warpgate/releases/tag/v0.27.6","tags":[]},{"url":"https://github.com/warp-tech/warpgate/security/advisories/GHSA-w9jj-vpw3-5r8f","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows a jump host key to be stored for a target address, enabling interception of user traffic and certificate authentication when exploited.","exploitability":"Exploitation requires control over a jump host and knowledge of the target address; relatively complex but feasible with proper conditions.","blast_radius":"If exploited, it could lead to significant data interception and unauthorized access in real-world scenarios involving SSH and certificate authentication.","remediation":"Update Warpgate to version 0.27.6 or later to mitigate this vulnerability.","tags":["ssh","interception","certificate","vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:24:22.120Z"}}