
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78134 is a vulnerability in the eap-peap and eap-ttls plugins of strongSwan, an open-source IPsec-based VPN solution. The flaw involves improper propagation of authentication details from inner EAP methods, where missing inner EAP authentication details can lead to incorrect identity binding and a potential authorization bypass. The CVE was inserted into Feedly's threat intelligence feed on September 7, 2026, with a Debian security advisory published shortly after. The estimated CVSS severity is Medium (Feedly, Debian Advisory).
The root cause lies in the strongSwan eap-peap and eap-ttls plugins' failure to correctly propagate authentication details from inner EAP authentication methods to the outer authentication layer (CWE classification not yet formally assigned, but consistent with CWE-287: Improper Authentication). In tunneled EAP protocols like PEAP and TTLS, an outer TLS tunnel is established first, and then an inner EAP method authenticates the user; if the inner method's identity is not correctly bound to the outer identity, an attacker may be able to exploit this mismatch. This could allow a malicious actor to leverage incomplete or missing inner EAP authentication details to bypass authorization checks (Feedly, Debian Advisory).
Successful exploitation of this vulnerability could allow an attacker to bypass authentication or authorization controls in VPN environments relying on strongSwan's PEAP or TTLS EAP methods. This could result in unauthorized network access, potentially exposing sensitive internal resources and enabling lateral movement within the affected network. The confidentiality and integrity of protected network segments could be compromised if an attacker gains unauthorized VPN access (Feedly, Debian Advisory).
As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation (Feedly). The CVE status remains "Reserved" with limited official technical disclosure. The vulnerability is detectable via Nessus plugins 343484 and 343507 (Tenable, Tenable). No EPSS score or CISA KEV catalog listing has been identified at this time.
Users should apply the patches distributed via the Debian security advisory (DSA referenced in msg00398) and equivalent updates from their Linux distribution. Organizations using strongSwan with EAP-PEAP or EAP-TTLS authentication should prioritize patching, as these are the affected components. As a temporary workaround, consider disabling EAP-PEAP and EAP-TTLS if not strictly required, or enforcing strict identity binding policies at the network perimeter (Debian Advisory, AUSCERT).
The vulnerability received coverage in the Linux security community, with pro-linux.de reporting on multiple strongSwan issues and LinuxCompatible.org including it in a daily security roundup alongside patches for PostgreSQL and 389 Directory Server (pro-linux.de, LinuxCompatible). No notable vendor statements or prominent researcher commentary beyond distribution-level advisories have been identified at this time.
Fix availability across major Linux distributions and their releases.
bookworm
strongswan
sid
strongswan: 6.1.0-1
trixie
strongswan: 6.0.1-6+deb13u7
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."