Authentication Bypass Vulnerability in FreeBSD WireGuard Driver
CVE-2026-58085
Currently unrated
What is CVE-2026-58085?
The vulnerability affects the WireGuard driver in FreeBSD where the MAC verification step is not checked after a decrypt operation, allowing attackers to inject forged packets. If an attacker can send UDP packets to a WireGuard endpoint and predict the receiver's replay window, they could exploit this flaw to bypass authentication checks, potentially altering encrypted traffic without detection. This weakness poses significant risks for data integrity and security in network communications.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
