libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
References
| Link | Resource |
|---|---|
| https://github.com/strongswan/strongswan/releases/tag/6.1.0 | Release Notes Vendor Advisory |
| https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html | Vendor Advisory Mitigation |
Configurations
History
16 Sep 2026, 19:37
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Strongswan
Strongswan strongswan |
|
| CPE | cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* | |
| References | () https://github.com/strongswan/strongswan/releases/tag/6.1.0 - Release Notes, Vendor Advisory | |
| References | () https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html - Vendor Advisory, Mitigation |
Information
Published : 2026-09-11 03:16
Updated : 2026-09-16 19:37
NVD link : CVE-2026-78135
Mitre link : CVE-2026-78135
CVE.ORG link : CVE-2026-78135
JSON object : View
Products Affected
strongswan
- strongswan
CWE
CWE-841
Improper Enforcement of Behavioral Workflow
