CVE-2026-63330: CWE-285: Improper Authorization in warp-tech warpgate
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermission::RecordingsView. Any authenticated regular user who identifies an active recording can subscribe to its WebSocket and receive real-time terminal input and output from proxied SSH, MySQL, or PostgreSQL sessions, including credentials, commands, and other sensitive data belonging to users and administrators. This issue is fixed in version 0.25.6.
AI Analysis
Technical Summary
Warpgate is an open source bastion host for SSH, HTTPS, and MySQL on Linux. Prior to version 0.25.6, the function api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects the recordings stream endpoint only with session authentication but does not enforce the require_admin_permission check for AdminPermission::RecordingsView. Consequently, any authenticated regular user who can identify an active recording can subscribe to its WebSocket stream and receive live terminal input and output from proxied sessions, including sensitive credentials and commands. This vulnerability is classified as CWE-285 (Improper Authorization) and CWE-862 (Missing Authorization). The vulnerability is resolved in version 0.25.6.
Potential Impact
An attacker with any authenticated user credentials can access real-time session recordings of other users, including administrators. This leads to exposure of sensitive information such as credentials and commands executed in SSH, MySQL, or PostgreSQL sessions. The confidentiality of user and administrative data is severely compromised. There is no indication of impact on integrity or availability.
Mitigation Recommendations
Upgrade warpgate to version 0.25.6 or later, where the require_admin_permission check for AdminPermission::RecordingsView is properly enforced on the recordings stream API endpoint. No other mitigation is indicated or required.
CVE-2026-63330: CWE-285: Improper Authorization in warp-tech warpgate
Description
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermission::RecordingsView. Any authenticated regular user who identifies an active recording can subscribe to its WebSocket and receive real-time terminal input and output from proxied SSH, MySQL, or PostgreSQL sessions, including credentials, commands, and other sensitive data belonging to users and administrators. This issue is fixed in version 0.25.6.
CVSS v3.1
Score 7.7high
Affected software
warp-tech
warpgate
pkg:github/warp-tech/warpgateRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Warpgate is an open source bastion host for SSH, HTTPS, and MySQL on Linux. Prior to version 0.25.6, the function api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects the recordings stream endpoint only with session authentication but does not enforce the require_admin_permission check for AdminPermission::RecordingsView. Consequently, any authenticated regular user who can identify an active recording can subscribe to its WebSocket stream and receive live terminal input and output from proxied sessions, including sensitive credentials and commands. This vulnerability is classified as CWE-285 (Improper Authorization) and CWE-862 (Missing Authorization). The vulnerability is resolved in version 0.25.6.
Potential Impact
An attacker with any authenticated user credentials can access real-time session recordings of other users, including administrators. This leads to exposure of sensitive information such as credentials and commands executed in SSH, MySQL, or PostgreSQL sessions. The confidentiality of user and administrative data is severely compromised. There is no indication of impact on integrity or availability.
Mitigation Recommendations
Upgrade warpgate to version 0.25.6 or later, where the require_admin_permission check for AdminPermission::RecordingsView is properly enforced on the recordings stream API endpoint. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-16T14:14:24.384Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab17f3e55bf5e2cf554e7c5
Added to database: 09/21/2026, 19:02:22 UTC
Last enriched: 09/21/2026, 19:16:31 UTC
Last updated: 09/22/2026, 00:02:43 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.