Vulnerability Description
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-33376?
CVE-2026-33376 is a vulnerability with a CVSS score of 7.4 (HIGH). When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128)...
How severe is CVE-2026-33376?
CVE-2026-33376 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33376?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.