CVE-2026-78135
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-78135 is a vulnerability in strongSwan's libcharon component affecting the handling of CREATE_CHILD_SA requests on unestablished IKE Security Associations (SAs). The flaw can result in the creation of a usable Child SA before authentication completes, potentially allowing unauthorized VPN tunnel establishment. The CVE status is currently listed as "Reserved," indicating that full vendor disclosure and patch details are still pending. The estimated CVSS severity is Medium, based on Feedly's category estimate (Feedly). Debian has issued a security announcement addressing this issue in strongSwan (Debian Advisory).

Technical details

The root cause lies in improper authentication state enforcement within libcharon, the IKEv2 charon daemon library used by strongSwan. Specifically, when processing CREATE_CHILD_SA requests, the library fails to verify that the parent IKE SA is fully authenticated before allowing Child SA creation, which maps to CWE-287 (Improper Authentication). An attacker capable of sending crafted IKEv2 messages to a vulnerable strongSwan endpoint could trigger this condition. No public proof-of-concept code or detailed technical write-up has been identified at this time (Feedly, Debian Advisory).

Impact

Successful exploitation could allow an unauthenticated or partially authenticated attacker to establish a usable IPsec Child SA, effectively bypassing the authentication requirement for VPN tunnel creation. This could lead to unauthorized network access through the VPN, potential interception or injection of traffic within the established tunnel, and exposure of network segments protected by the IPsec policy. The integrity and confidentiality of communications routed through the affected strongSwan instance may be compromised (Feedly).

Exploitability

As of the time of this report, there is no confirmed evidence of in-the-wild exploitation, no public proof-of-concept exploit code, and no CISA KEV catalog listing for CVE-2026-78135 (Feedly). The CVE remains in "Reserved" status, meaning full technical details have not been officially published by the CVE Numbering Authority. Nessus detection plugins (IDs 343484 and 343495) have been released by Tenable, indicating the vulnerability is detectable in scanning contexts (Tenable, Tenable). No threat actor attribution has been reported.

Mitigation and workarounds

Debian has issued a security advisory (DSA) addressing CVE-2026-78135 in strongSwan, and users of Debian-based systems should apply the available package updates immediately (Debian Advisory). Users of other Linux distributions should monitor their respective vendor advisories for patched strongSwan packages. As a workaround, administrators can restrict IKEv2 traffic to trusted peers using firewall rules and ensure that strongSwan is not exposed to untrusted networks until a patch is applied. Regularly auditing established IPsec SAs for unexpected or unauthorized tunnels is also recommended.

Community reactions

The vulnerability has been covered in German Linux security news outlet Pro-Linux (Pro-Linux) and noted in a Linux security roundup by LinuxCompatible (LinuxCompatible). AusCERT has also published a bulletin (ESB-2026.10585) referencing the issue (AusCERT). Broader community or social media discussion has been limited given the Reserved CVE status and absence of a public technical write-up.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

strongswan

Affected

sid

strongswan: 6.1.0-1

Fixed

trixie

strongswan: 6.0.1-6+deb13u7

Fixed

Ubuntu

Affected

bionic (esm-infra)

strongswan

Unknown

bionic (fips-updates)

strongswan

Unknown

bionic (fips)

strongswan

Unknown

devel

strongswan: 6.0.7-1ubuntu3

Affected

focal (esm-infra)

strongswan

Unknown

focal (fips-updates)

strongswan

Unknown

focal (fips)

strongswan

Unknown

jammy

strongswan

Unknown

SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78135NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78134NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78133NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78132NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78131NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management