Description
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Improper Authorization
Action: Immediate Patch
AI Analysis

Impact

A flaw in the eap-ttls and eap-peap plugins of strongSwan allows an attacker to bypass inner EAP identity checks, potentially leading to unauthorized access to protected resources. This weakness is classified under CWE-863, which denotes Incorrect Authorization. The vulnerability does not directly disclose or modify data, but it removes a critical gate that validates the identity presented during the TLS inner EAP phase, thereby enabling an attacker to impersonate a legitimate client or server without detection. No additional disclosures or evidence of compromise were reported in the advisory, so the impact is limited to successful exploitation of the authentication process.

Affected Systems

strongSwan VPN software versions 4.5.0 through 6.0.7 are affected. The issue is present in the eap-ttls and eap-peap authentication modules, which are commonly used in enterprise VPN deployments. The most recent release notes at https://github.com/strongswan/strongswan/releases/tag/6.1.0 indicate that the vulnerability has been addressed in version 6.1.0, but no specific notes are provided to confirm the fix. Administrators should check that their deployment falls within the vulnerable range and whether any custom modules or patches are in use.

Risk and Exploitability

The CVSS score of 7.1 signifies a high severity impact, but without an EPSS score the likelihood of immediate exploitation remains unknown. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. The attack vector is inferred to be remote, as the affected plugin is part of the IPsec VPN service exposed to network traffic. Successful exploitation would primarily allow an attacker to authenticate incorrectly and gain unauthorized access, potentially escalating privileges if additional vulnerabilities are present. Administrators should treat this as a high priority remediation item due to the serious nature of unauthorized access.

Generated by OpenCVE AI on September 11, 2026 at 04:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to strongSwan 6.1.0 or later, which contains the fix for the inner EAP identity check issue.
  • If an immediate upgrade is not possible, apply configuration changes that enforce the presence and correctness of the inner EAP identity in eap-ttls and eap-peap exchanges; consult the strongSwan documentation for settings that control identity matching.
  • Consider disabling the vulnerable eap-ttls and eap-peap plugins entirely if they are not required for your deployment, thereby removing the attack surface.
  • Monitor VPN authentication logs for anomalous EAP identity patterns and alert on repeated failures that may indicate probing or exploitation attempts.

Generated by OpenCVE AI on September 11, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Imprecise Access Control in eap-ttls/eap-peap Plugins of strongSwan

Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-863
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T14:14:06.979Z

Reserved: 2026-08-22T23:39:46.284Z

Link: CVE-2026-78134

cve-icon Vulnrichment

Updated: 2026-09-11T14:13:59.471Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:34.910

Modified: 2026-09-14T20:06:44.303

Link: CVE-2026-78134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:00:03Z

Weaknesses