Description
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (potential crash)
Action: Patch
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the eap-aka plugin of strongSwan versions 4.1.10 through 6.0.7. The flaw can cause the software to crash during authentication processing, resulting in a denial of service and potentially disrupting VPN connections for affected users. The weakness is categorized as CWE‑476.

Affected Systems

The affected product isSwan strongswan, and the version range impacted is 4.1.10 to 6.0.7 inclusive. No other vendors or products are listed in the data.

Risk and Exploitability

The CVSS score of 5.9 denotes moderate severity, and the EPSS score is not available, indicating no published data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. The flaw is triggered when the eap-aka plugin processes authentication traffic, so the likely attack vector is remote, via an attacker who can send crafted EAP‑AKA messages during the VPN handshake. The exact exploitation conditions are not fully described in the source data, so the assessment assumes that the attacker can reach the authentication service.

Generated by OpenCVE AI on September 11, 2026 at 03:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the newest strongSwan release that contains the eap‑aka fix, such as version 6.1.0 according to the vendor advisory.
  • If the eap‑aka plugin is not required, disable or remove it from the installation to eliminate the code path that can dereference a NULL pointer.
  • Configure the VPN to reject or monitor authentication attempts for anomalous EAP‑AKA traffic, and review logs for crashes that may indicate exploitation attempts.

Generated by OpenCVE AI on September 11, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in strongSwan eap-aka Plugin

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-476
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:18:37.226Z

Reserved: 2026-08-22T23:27:32.767Z

Link: CVE-2026-78126

cve-icon Vulnrichment

Updated: 2026-09-14T14:57:05.332Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:33.920

Modified: 2026-09-14T20:09:26.640

Link: CVE-2026-78126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:30:05Z

Weaknesses