VDB
CVE-2026-78135
CVE-2026-78135
PUBLISHED
CVSS 5.6 MEDIUM
Reported by mitre · Published September 11, 2026
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Risk Scores
CVSS 3.1
5.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| strongSwan | strongSwan | 5.9.7 |
| strongSwan | strongSwan | 5.9.7, 5.9.7 |
| strongswan | strongswan | 5.9.7, 5.9.7 |
Timeline
- Sep 10, 2026 CVE Published
- Sep 11, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 15, 2026 CVE Updated
- Sep 16, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score