
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34873 is a critical improper authentication vulnerability in Mbed TLS that allows client impersonation during TLS 1.3 session resumption. It affects Mbed TLS versions 3.5.0 through 3.6.5 (fixed in 3.6.6) and 4.0.0 (fixed in 4.1.0), maintained by both ARM and Trusted Firmware. The vulnerability was published on April 1, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, Mbed TLS Advisory).
The vulnerability is classified as CWE-287 (Improper Authentication), stemming from a flaw in how Mbed TLS handles the TLS 1.3 session resumption process. During session resumption, the library fails to adequately verify the identity of the resuming client, allowing an attacker to impersonate a legitimate client without possessing the original client's credentials. The attack requires no privileges, no user interaction, and is exploitable remotely over the network with low complexity, making it particularly dangerous in environments relying on Mbed TLS for mutual authentication (GitHub Advisory, Mbed TLS Advisory).
Successful exploitation allows an unauthenticated remote attacker to impersonate a legitimate TLS client during session resumption, compromising both the confidentiality and integrity of TLS-protected communications. This can enable unauthorized access to sensitive data, bypass client certificate authentication controls, and facilitate adversary-in-the-middle (AiTM) attacks on affected connections. Availability is not directly impacted, but the authentication bypass could grant attackers access to backend systems or services that rely on TLS client identity for access control (GitHub Advisory, Mbed TLS Advisory).
tlsx or nmap with TLS scripts).pre_shared_key extension) where the resuming client IP or certificate identity differs from the original session; anomalous authentication successes for high-privilege clients from unusual source addresses.Upgrade Mbed TLS to version 3.6.6 or later (for the 3.x branch) or version 4.1.0 or later (for the 4.x branch) to remediate this vulnerability (Mbed TLS Advisory). As a temporary workaround where patching is not immediately possible, disabling TLS 1.3 session resumption (PSK/ticket-based resumption) in the Mbed TLS configuration can mitigate the risk. Organizations should also monitor for suspicious session resumption activity in TLS 1.3 traffic as a compensating control. OpenSUSE and Fedora package updates incorporating the fix have been released (OpenSUSE Security Announce).
The Mbed TLS project published a dedicated security advisory detailing the vulnerability and its fix (Mbed TLS Advisory). Splunk also issued an advisory (SVD-2026-0512) referencing this CVE, indicating downstream impact on products using Mbed TLS (Splunk Advisory). Linux distribution maintainers for OpenSUSE and Fedora have released updated packages. No significant social media controversy or notable independent researcher commentary has been identified beyond standard vulnerability tracking coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."