External risk intelligence

Warpgate SSO Open Redirect and Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-58491

Warpgate is a bastion host designed to act as a gateway for SSH, HTTPS, and MySQL traffic. By definition, such infrastructure is intended to be network-accessible to facilitate remote access, making its management and SSO interfaces typically exposed to the environments they are configured to protect or to the public internet.

Cross-site Scripting

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Warpgate, an open-source tool used for secure access to systems. The issue, discovered in versions prior to 0.25.5, could allow an attacker to execute malicious code within the Warpgate environment, potentially leading to unauthorized access to session data and actions. The main concern is confirming if Warpgate is in use and if the affected functions are exposed.

  • Attackers could compromise sensitive system access.
  • It impacts secure gateways and potential data exposure.
  • Confirm Warpgate relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can entice a victim into clicking a crafted link that targets the Warpgate bastion host's single sign-on (SSO) endpoint. If the victim is authenticated, this can lead to arbitrary code execution within the victim's browser session, potentially exposing sensitive session data and enabling unauthorized actions. An open redirect vulnerability is also present.

  • No authentication required to initiate.
  • Victim follows a crafted SSO link.
  • Session data theft and unauthorized actions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute malicious markup and JavaScript within the Warpgate session of an authenticated user. When a victim clicks a crafted link and completes the single sign-on (SSO) process, this could lead to the execution of arbitrary code in the context of the Warpgate origin, potentially exposing session data and enabling unauthorized actions via user or administrator APIs.

  • Session data and user actions.
  • Crafted links and SSO completion.
  • Unauthorized access to sensitive information.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security and platform teams are likely responsible for addressing this vulnerability in Warpgate, as it impacts an open-source bastion host used for critical access control. The immediate first step is to inventory all Warpgate instances, determine their network exposure, and identify business-critical deployments. Once confirmed, the accountable owner should be engaged to plan remediation, prioritizing affected systems based on risk and potential impact.

  • Identify all Warpgate instances.
  • Verify network exposure and critical systems.
  • Plan remediation with accountable owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Warpgate?

Warpgate is an open-source bastion host for Linux environments. It serves as a centralized gateway to manage and secure remote access for SSH, HTTPS, and MySQL traffic, effectively acting as a bridge between users and your internal infrastructure.

What does CWE-79 mean for CVE-2026-58491?

CWE-79 refers to Cross-Site Scripting (XSS). In this CVE, the vulnerability allows an attacker to inject malicious scripts into the Warpgate SSO process. When a victim interacts with a crafted link, this code executes in their browser, potentially granting the attacker access to the victim's Warpgate session data and capabilities.

How is this vulnerability triggered?

An attacker must entice an authenticated user to click a specially crafted link that leads to the Warpgate SSO return endpoint. Simply accessing the site normally does not trigger the bug; the process specifically requires the victim to follow the malicious link and complete the SSO authentication flow.

Is my instance at risk?

According to Halo Surface Signal, Warpgate is designed to facilitate remote access and is often deployed in network-accessible locations, sometimes facing the public internet. If your instance is exposed to the network where users interact with SSO, you should evaluate it as potentially reachable by this attack.

How do I secure my environment?

The primary step is to upgrade your deployment to version 0.25.5 or later, which contains the fix for this issue. Before patching, perform an inventory of all your Warpgate instances to identify and prioritize those that are network-facing or handle critical system access.

References