CVE-2026-78135

Summary

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

Affected Software

VendorProductVersion RangeStatus
strongSwanstrongSwan5.9.7 < 6.1.0affected

Weaknesses

  • CWE-841: CWE-841 Improper Enforcement of Behavioral Workflow

References