NULL Pointer Dereference in strongSwan EAP-AKA Plugin
CVE-2026-78126

5.9MEDIUM

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
11 September 2026

What is CVE-2026-78126?

The strongSwan software, specifically versions ranging from 4.1.10 to 6.0.7, contains a vulnerability in the eap-aka plugin that allows a NULL pointer dereference, potentially leading to application crashes or instability. This flaw can be exploited in certain situations, posing risks to secure communication protocols. It is important for users to update to the latest version of strongSwan to mitigate this issue and ensure the integrity and security of their network communications.

Affected Version(s)

strongSwan 4.1.10 < 6.1.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.