CVE-2014-2595: Barracuda Web Application Firewall

Critical severity, CVSS 9.8. EPSS: 16.9% chance of exploitation in the next 30 days.

Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

Affected products

  • Barracuda Web Application Firewall: version 7.8.1.013 only

Published 2020-02-12. Last modified 2026-06-17.