Overview
What is CVE-2026-78135?
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Vulnerability intelligence
CVE-2026-78135 and is rated Medium severity with a CVSS score of 5.6. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.