
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78135 is a vulnerability in strongSwan's libcharon component affecting the handling of CREATE_CHILD_SA requests on unestablished IKE Security Associations (SAs). The flaw can result in the creation of a usable Child SA before authentication completes, potentially allowing unauthorized VPN tunnel establishment. The CVE status is currently listed as "Reserved," indicating that full vendor disclosure and patch details are still pending. The estimated CVSS severity is Medium, based on Feedly's category estimate (Feedly). Debian has issued a security announcement addressing this issue in strongSwan (Debian Advisory).
The root cause lies in improper authentication state enforcement within libcharon, the IKEv2 charon daemon library used by strongSwan. Specifically, when processing CREATE_CHILD_SA requests, the library fails to verify that the parent IKE SA is fully authenticated before allowing Child SA creation, which maps to CWE-287 (Improper Authentication). An attacker capable of sending crafted IKEv2 messages to a vulnerable strongSwan endpoint could trigger this condition. No public proof-of-concept code or detailed technical write-up has been identified at this time (Feedly, Debian Advisory).
Successful exploitation could allow an unauthenticated or partially authenticated attacker to establish a usable IPsec Child SA, effectively bypassing the authentication requirement for VPN tunnel creation. This could lead to unauthorized network access through the VPN, potential interception or injection of traffic within the established tunnel, and exposure of network segments protected by the IPsec policy. The integrity and confidentiality of communications routed through the affected strongSwan instance may be compromised (Feedly).
As of the time of this report, there is no confirmed evidence of in-the-wild exploitation, no public proof-of-concept exploit code, and no CISA KEV catalog listing for CVE-2026-78135 (Feedly). The CVE remains in "Reserved" status, meaning full technical details have not been officially published by the CVE Numbering Authority. Nessus detection plugins (IDs 343484 and 343495) have been released by Tenable, indicating the vulnerability is detectable in scanning contexts (Tenable, Tenable). No threat actor attribution has been reported.
Debian has issued a security advisory (DSA) addressing CVE-2026-78135 in strongSwan, and users of Debian-based systems should apply the available package updates immediately (Debian Advisory). Users of other Linux distributions should monitor their respective vendor advisories for patched strongSwan packages. As a workaround, administrators can restrict IKEv2 traffic to trusted peers using firewall rules and ensure that strongSwan is not exposed to untrusted networks until a patch is applied. Regularly auditing established IPsec SAs for unexpected or unauthorized tunnels is also recommended.
The vulnerability has been covered in German Linux security news outlet Pro-Linux (Pro-Linux) and noted in a Linux security roundup by LinuxCompatible (LinuxCompatible). AusCERT has also published a bulletin (ESB-2026.10585) referencing the issue (AusCERT). Broader community or social media discussion has been limited given the Reserved CVE status and absence of a public technical write-up.
Fix availability across major Linux distributions and their releases.
bookworm
strongswan
sid
strongswan: 6.1.0-1
trixie
strongswan: 6.0.1-6+deb13u7
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."