libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Medium CVSS 5.6
Summary
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/strongswan/strongswan/releases/tag/6.1.0 Release Notes
- https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html Vendor Advisory
Timeline
- nvd_ingest NVD