CVE-2026-78134

Summary

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Affected Software

VendorProductVersion RangeStatus
strongSwanstrongSwan4.5.0 < 6.1.0affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

References