strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
References
| Link | Resource |
|---|---|
| https://github.com/strongswan/strongswan/releases/tag/6.1.0 | Patch Release Notes Vendor Advisory |
| https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-11 02:18
Updated : 2026-09-14 20:06
NVD link : CVE-2026-78134
Mitre link : CVE-2026-78134
CVE.ORG link : CVE-2026-78134
JSON object : View
Products Affected
strongswan
- strongswan
CWE
CWE-863
Incorrect Authorization
