Improper Certificate Validation in Gaia - CVE-2026-50752
Published: June 9, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct a man-in-the-middle attack.
The vulnerability exists due to improper certificate validation in the IKEv1 key exchange certificate validation logic when establishing a VPN site-to-site connection using certificate-based authentication. A remote attacker can present a crafted certificate to conduct a man-in-the-middle attack.
The issue applies only to VPN site-to-site configurations that use IKEv1 with certificate-based authentication, and does not affect pre-shared key authentication, Dynamic IP gateways, or Large Scale VPN communities.