CVE-2026-78134
largeIncorrect Access Control in strongSwan eap-ttls/eap-peap Plugins
strongSwan 4.5.0 through 6.0.7 contain an incorrect access control flaw (CWE-863) in the eap-ttls and eap-peap IKEv2 authentication plugins, where the inner EAP identity used inside the TTLS/PEAP tunnel can be missing or mismatched with the outer IKEv2 identity. An attacker who completes inner authentication with one identity can have the connection authorized under a different identity, since the gateway may not correctly bind the authenticated inner identity to the authorization decision. This can let a low-privilege attacker with valid credentials for one account obtain the access rights of another identity, consistent with the 7.1 (high) CVSS score with high confidentiality and integrity impact and low availability impact. Only deployments that use IKEv2 EAP authentication via the eap-ttls or eap-peap plugins are affected; sites relying on certificate or other authentication methods are not. No public proof-of-concept, listing in CISA KEV, or confirmed in-the-wild exploitation is currently known.
What to do: Track the strongSwan project's advisories for a fixed release beyond 6.0.7 and upgrade promptly. As interim mitigation, disable the eap-ttls and eap-peap plugins if they are not required, or enforce strict matching between the inner EAP identity and the outer IKEv2 identity in gateway or RADIUS policy. Review VPN authentication logs for sessions in which the inner and outer identities differ.
| strongSwan Project strongSwan | 4.5.0 through 6.0.7 (deployments using the eap-ttls or eap-peap plugins for IKEv2 EAP authentication) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
- Vendors
- strongswan
- Products
- strongswan
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.