Acme Edge Gateway authentication bypass

An authentication boundary flaw may allow a remote unauthenticated actor to access administrative functions on affected gateways.

Published 24 May 2026Updated 1 Sep 202633 sources
CVSS 8.8 HIGHPoC CANDIDATE△ CISA KEV

What happened

A flaw in the authentication boundary of Acme Edge Gateway allows a remote unauthenticated actor to access administrative endpoints intended for authorized users. The issue stems from improper validation of session state before routing requests to privileged functionality.

Affected versions

Edge Gateway: ≤ 3.2.4 Fixed: 3.2.5.

Why it matters

Successful use can result in administrative access to the gateway, including configuration changes and service disruption. Internet-facing, centrally deployed gateways have the highest exposure.

Detection & mitigation

  • Upgrade to Acme Edge Gateway 3.2.5 or later.
  • Monitor for unusual administrative actions and configuration changes.
  • Restrict administrative interfaces to trusted networks.
  • Review gateway access logs for unauthenticated requests to administrative paths.

Public PoC references