Access Control Flaw in strongSwan EAP Plugins Affecting Multiple Versions
CVE-2026-78134
7.1HIGH
What is CVE-2026-78134?
The strongSwan implementation, including versions 4.5.0 through 6.0.7, contains an access control issue in its EAP-TTLS and EAP-PEAP plugins. This vulnerability arises from a potential missing or mismatched inner EAP identity, which can expose users to unauthorized access and security breaches. Administrators utilizing these versions should review their configurations and apply the necessary updates to mitigate this risk, ensuring their network communications remain secure and unaffected by this flaw.
Affected Version(s)
strongSwan 4.5.0 < 6.1.0
