Vulnerability in Crux Agent Affects WireGuard Configuration
CVE-2026-107785

6.3MEDIUM

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107785?

The Crux Agent, prior to version 2.0.3, has a vulnerability that allows improper use of the bilocation key as a preshared key in WireGuard configurations. When establishing a peering session that utilizes SHA-512, the resulting key length is mistakenly set to 64 bytes, which exceeds the required size for WireGuard. Due to insufficient validation, the agent attempts to apply this incorrect key during the wg set command, leading to failures in updating the live tunnel configuration. As a result, the existing preshared key remains in use until the tunnel is restarted, at which point it fails to initiate if the 32-byte key has never been negotiated successfully. This security flaw can put users at risk, especially in scenarios involving traffic interception by adversaries with access to advanced computational resources.

Affected Version(s)

Crux Agent 1.9.0 < 2.0.3

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.