Junglewise Threat Intelligence

CVE-2026-2624: ePati Antikor NGFW authentication bypass in critical functions

CVE-2026-2624 · Severity: critical · CVSS 9.8 · Published 2026-02-25

Executive brief

A critical security flaw has been identified in the Antikor Next Generation Firewall, a device used to protect corporate networks from cyber threats. This vulnerability allows an unauthorized person to bypass security checks and access sensitive administrative functions without a password. If exploited, an attacker could take full control of the firewall, potentially leading to a complete network compromise or service outage.

Technical details

A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the ePati Antikor Next Generation Firewall (NGFW). The flaw is located within the handling of critical administrative functions, where the system fails to verify the identity of the requester. An unauthenticated attacker can exploit this over the network with low complexity and no user interaction. Successful exploitation allows the attacker to bypass authentication mechanisms entirely, granting them full access to the device's management capabilities. The issue affects versions starting from v.2.0.1298 and is fixed in version v.2.0.1301.

Affected products

  • ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) v.2.0.1298 to v.2.0.1301 (exclusive)

Timeline

  • 2026-02-25: disclosed
  • 2026-02-25: advisory

References