Overview
What is CVE-2026-78134?
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
Vulnerability intelligence
CVE-2026-78134 and is rated High severity with a CVSS score of 7.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.