TLS Vulnerability in wolfSSL Affecting Raw Public Key Authentication
CVE-2026-89136

8.3HIGH

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-89136?

A vulnerability exists in wolfSSL that affects the TLS 1.2, 1.3, and DTLS 1.2 protocols when using Raw Public Key (RPK) authentication. Specifically, the client side of these connections can erroneously accept unsolicited server certificates of type Raw Public Key. This issue allows malicious actors to bypass standard authentication procedures, as the server can present itself without proper verification. RPK is not enabled by default and requires specific configurations to be activated, such as --enable-rpk. Users are advised to review their configurations and ensure that they implement adequate security measures to mitigate this risk.

Affected Version(s)

wolfSSL 5.6.0 <= 5.9.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christos Papakonstantinou (Cantina Security)
.