Junglewise Threat Intelligence

CVE-2026-90823: FatPipe MPVPN WARP IPVPN stack buffer overflow in auth_user_pass

CVE-2026-90823 · Severity: critical · CVSS 9.8 · Published 2026-09-17

Technologies: Fatpipe WARP, Fatpipe IPVPN. Vendors: Fatpipe.

Executive brief

FatPipe's MPVPN, WARP, and IPVPN appliances are WAN optimization and VPN devices used to manage multi-site network connectivity. An unauthenticated attacker with network access to the management interface (which is disabled by default) can send a crafted request to trigger a buffer overflow in the authentication service, potentially gaining complete control of the appliance. This impacts network availability and security across connected sites.

Technical details

A stack-based buffer overflow exists in the /usr/sbin/auth_user_pass binary on affected appliances. The vulnerability is triggered when an unchecked copy operation writes attacker-controlled data into a fixed-size stack buffer, allowing stack corruption and arbitrary code execution as root. The attack vector is the management interface (typically disabled by default); an attacker must first gain network access to this interface through misconfiguration or network exposure. While no active exploitation in the wild has been reported, the 9.8 CVSS score reflects the severity—authentication is not required and code execution as root is achievable. FatPipe has marked firmware version 10.1.2r60p100 as end-of-life; customers must upgrade to supported releases for a patch.

Affected products

  • FatPipe MPVPN 10.1.2r60p100
  • FatPipe WARP 10.1.2r60p100
  • FatPipe IPVPN 10.1.2r60p100

Timeline

  • 2026-09-17: disclosed

References

Related threats