Improper Authentication in strongSwan - CVE-2026-78135

 

Improper Authentication in strongSwan - CVE-2026-78135

Published: September 22, 2026


Vulnerability identifier: #VU151583
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78135
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to establish a usable Child SA before authentication completes.

The vulnerability exists due to improper state validation in libcharon's task manager when processing CREATE_CHILD_SA requests on unestablished IKE SAs. A remote attacker can send a CREATE_CHILD_SA request during EAP authentication to establish a usable Child SA before authentication completes.

Exploitation requires EAP authentication and either no configured IP address pool or an explicit remote traffic selector.


Affected software

strongSwan
Debian Linux
strongswan (Debian package)

How to mitigate CVE-2026-78135

Install security update from vendor's website.

strongSwan - update to 6.1.0
strongswan (Debian package) - update to 6.0.1-6+deb13u7

External References

Related Security Bulletins