Authentication Bypass by Primary Weakness in cURL - CVE-2026-8932

 

Authentication Bypass by Primary Weakness in cURL - CVE-2026-8932

Published: June 24, 2026


Vulnerability identifier: #VU135079
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8932
CWE-ID: CWE-305
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass client certificate authentication.

The vulnerability exists due to authentication bypass by primary weakness in libcurl connection reuse logic when reusing a previously established connection after changing mTLS client certificate settings. A remote user can reuse a connection with mismatched client certificate configuration to bypass client certificate authentication.

The issue affects libcurl and does not affect the curl command line tool.


Affected software

cURL
LANTIME Operating System Firmware (LTOS)

How to mitigate CVE-2026-8932

Install security update from vendor's website.

cURL - update to 8.21.0
LANTIME Operating System Firmware (LTOS) - update to 7.10.013

External References

Related Security Bulletins