Junglewise Threat Intelligence

CVE-2026-78134: strongSwan incorrect identity binding in EAP-PEAP and EAP-TTLS

CVE-2026-78134 · Severity: high · CVSS 7.1 · Published 2026-09-11

Technologies: strongSwan. Vendors: strongSwan.

Executive brief

strongSwan is an open-source VPN and IPsec authentication system widely used in enterprise networks and VPN gateways. A flaw in its EAP-PEAP and EAP-TTLS authentication plugins allows an authenticated attacker to impersonate other users or claim their network resources (virtual IPs) by supplying a different identity during the outer authentication phase while using legitimate credentials internally. This can lead to unauthorized access to network resources and disruption of other users' connections.

Technical details

The vulnerability is an incorrect access control issue in the eap-peap and eap-ttls plugins where the inner EAP method's identity is not properly propagated to the outer IKE/EAP identity, or a mismatch occurs between them. The root cause is that the IKE/EAP identity—which is used for critical authorization decisions including configuration selection, uniqueness checks, and virtual IP assignment—may not match the authenticated inner EAP identity. An attacker with valid credentials can exploit this by claiming a different identity during the initial EAP-Identity exchange while authenticating with their own credentials in the tunneled inner EAP method. The attack requires the attacker to have valid authentication credentials and EAP-PEAP or EAP-TTLS to be enabled on the server. The fix is included in strongSwan 6.1.0 and patches are available for versions 5.3.0 and newer.

Affected products

  • strongSwan strongSwan 4.5.0 through 6.0.7

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in version 6.1.0 released 2026-09-07

References

Related threats