Improper authentication in Gaia - CVE-2026-50751
Published: June 9, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a logic error in the Remote Access and Mobile Access certificate validation during deprecated IKEv1 key exchange. A remote attacker can establish a remote access VPN connection without a valid user password and gain access to network resources available to authenticated users.
Note, the vulnerability is being actively exploited in the wild.