Description
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Published: 2026-09-11
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

libcharon in strongSwan versions 5.9.7 through 6.0.7 mishandles the IKEv2 state machine, specifically the CREATE_CHILD_SA request handling. This mismanagement permits an attacker to bypass authentication checks, effectively allowing unauthorized access to protected services or resources. The underlying weakness maps to CWE-841, which denotes mismanagement of platform or system resources that can lead to security problems.

Affected Systems

The affected product is strongSwan, a VPN IPsec implementation. Versions from 5.9.7 up to and including 6.0.7 are vulnerable. The vulnerability stems from the libcharon component, which handles IKEv2 negotiations. Systems running any of these versions in a networked environment, especially those configured to accept IKEv2 connections, are impacted.

Risk and Exploitability

The CVSS score of 5.6 indicates a medium severity vulnerability. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is the network: an attacker who can send crafted CREATE_CHILD_SA messages in an IKEv2 exchange can trigger the misbehavior. Because the flaw allows bypassing authentication, it can enable subsequent unauthorized actions; however, exploitability depends on network access and the configuration of the strongSwan instance.

Generated by OpenCVE AI on September 11, 2026 at 05:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to strongSwan 6.1.0 or later, which removes the IKEv2 state machine flaw
  • If an upgrade is not possible immediately, temporarily block or disable IKEv2 traffic by configuring firewall rules to reject or drop packets with protocol ID 50 (IKEv2)
  • Review and tighten IKEv2 peer authentication by enforcing client certificates and restricting allowed IP ranges to trusted networks

Generated by OpenCVE AI on September 11, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via CREATE_CHILD_SA in strongSwan IKEv2

Fri, 11 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-841
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T15:32:51.934Z

Reserved: 2026-08-22T23:41:22.635Z

Link: CVE-2026-78135

cve-icon Vulnrichment

Updated: 2026-09-15T15:32:48.408Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T03:16:23.160

Modified: 2026-09-16T19:37:30.467

Link: CVE-2026-78135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:08Z

Weaknesses
  • CWE-841

    Improper Enforcement of Behavioral Workflow