Improper Authentication in wolfSSL - CVE-2026-93304
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate a server.
The vulnerability exists due to improper state management in the TLS 1.2 and DTLS 1.2 handshake when receiving an out-of-order ChangeCipherSpec message before ClientKeyExchange. A remote attacker can send an out-of-order ChangeCipherSpec message to impersonate a server.
Certificate-suite exploitation requires a man-in-the-middle position, while PSK connections can be attacked by a fake server without knowledge of the PSK.