CVE-2022-3320: Cloudflare WARP
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and allowed bypassing administrative restrictions on a Zero Trust enrolled endpoint.
Affected products
- Cloudflare WARP: before 2022.8.857.0 (fixed in 2022.8.857.0); before 2022.8.861.0 (fixed in 2022.8.861.0); before 2022.8.936 (fixed in 2022.8.936)
Published 2022-10-28. Last modified 2026-06-17.