Improper Authentication in strongSwan - CVE-2026-78135
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to establish a usable Child SA before authentication completes.
The vulnerability exists due to improper state validation in libcharon's task manager when processing CREATE_CHILD_SA requests on unestablished IKE SAs. A remote attacker can send a CREATE_CHILD_SA request during EAP authentication to establish a usable Child SA before authentication completes.
Exploitation requires EAP authentication and either no configured IP address pool or an explicit remote traffic selector.
Affected software
Debian Linux
strongswan (Debian package)
How to mitigate CVE-2026-78135
strongswan (Debian package) - update to 6.0.1-6+deb13u7