Improper Certificate Validation in wolfSSL - CVE-2026-89136

 

Improper Certificate Validation in wolfSSL - CVE-2026-89136

Published: October 5, 2026


Vulnerability identifier: #VU153283
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89136
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass server authentication.

The vulnerability exists due to improper certificate validation in raw public key handling when processing an unsolicited server_cert_type=RawPublicKey. A remote attacker can send an unsolicited raw public key certificate type to bypass server authentication.

Only builds with raw public key support enabled are affected.


Affected software

wolfSSL

How to mitigate CVE-2026-89136

Install security update from vendor's website.

wolfSSL - update to 5.9.4

External References

Related Security Bulletins