Authentication Bypass by Primary Weakness in wolfSSL - CVE-2026-94419
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate a previously authenticated server.
The vulnerability exists due to improper session management in the process-global SessionCache when handling legacy client session references. A remote attacker can cause a session cache entry to be overwritten through a matching TLS session ID to impersonate a previously authenticated server.
The issue requires the legacy wolfSSL_get_session() or SSL_get_session() flow followed by wolfSSL_set_session() and affects TLS 1.2 and earlier or DTLS 1.2 and earlier.