Access Control Flaw in strongSwan EAP Plugins Affecting Multiple Versions
CVE-2026-78134

7.1HIGH

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
11 September 2026

What is CVE-2026-78134?

The strongSwan implementation, including versions 4.5.0 through 6.0.7, contains an access control issue in its EAP-TTLS and EAP-PEAP plugins. This vulnerability arises from a potential missing or mismatched inner EAP identity, which can expose users to unauthorized access and security breaches. Administrators utilizing these versions should review their configurations and apply the necessary updates to mitigate this risk, ensuring their network communications remain secure and unaffected by this flaw.

Affected Version(s)

strongSwan 4.5.0 < 6.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.