ZeroHour

CVE-2026-78134

large

Incorrect Access Control in strongSwan eap-ttls/eap-peap Plugins

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

strongSwan 4.5.0 through 6.0.7 contain an incorrect access control flaw (CWE-863) in the eap-ttls and eap-peap IKEv2 authentication plugins, where the inner EAP identity used inside the TTLS/PEAP tunnel can be missing or mismatched with the outer IKEv2 identity. An attacker who completes inner authentication with one identity can have the connection authorized under a different identity, since the gateway may not correctly bind the authenticated inner identity to the authorization decision. This can let a low-privilege attacker with valid credentials for one account obtain the access rights of another identity, consistent with the 7.1 (high) CVSS score with high confidentiality and integrity impact and low availability impact. Only deployments that use IKEv2 EAP authentication via the eap-ttls or eap-peap plugins are affected; sites relying on certificate or other authentication methods are not. No public proof-of-concept, listing in CISA KEV, or confirmed in-the-wild exploitation is currently known.

What to do: Track the strongSwan project's advisories for a fixed release beyond 6.0.7 and upgrade promptly. As interim mitigation, disable the eap-ttls and eap-peap plugins if they are not required, or enforce strict matching between the inner EAP identity and the outer IKEv2 identity in gateway or RADIUS policy. Review VPN authentication logs for sessions in which the inner and outer identities differ.

Affected
strongSwan Project strongSwan4.5.0 through 6.0.7 (deployments using the eap-ttls or eap-peap plugins for IKEv2 EAP authentication)
Estimated exposure
large≈10,000–100,000 VPN gateways/clients with EAP-TTLS or EAP-PEAP enabled (a subset of strongSwan's multi-million install base) — strongSwan ships as a standard IPsec/IKEv2 stack in many Linux distributions and embedded and enterprise VPN gateways, giving an install base in the millions, but only the non-default subset of deployments that load the eap-ttls or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Vendors
strongswan
Products
strongswan
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.