Authentication Bypass by Spoofing in strongSwan - CVE-2026-78134
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization controls by impersonating another user.
The vulnerability exists due to improper authentication of inner EAP identities in the eap-peap and eap-ttls plugins when processing tunneled EAP authentication. A remote user can authenticate with valid credentials while claiming another user's identity during the outer EAP-Identity exchange to bypass authorization controls by impersonating another user.
Exploitation requires the use of EAP-PEAP or EAP-TTLS tunneling authentication protocols.
Affected software
Debian Linux
strongswan (Debian package)
How to mitigate CVE-2026-78134
strongswan (Debian package) - update to 6.0.1-6+deb13u7