Junglewise Threat Intelligence

CVE-2026-78135: strongSwan libcharon authentication bypass in IKEv2 CREATE_CHILD_SA handling

CVE-2026-78135 · Severity: medium · CVSS 5.6 · Published 2026-09-11

Technologies: strongSwan. Vendors: strongSwan.

Executive brief

strongSwan is an IPsec VPN implementation used to establish secure tunnels between networks and endpoints. Due to improper state validation in the IKEv2 protocol implementation, an unauthenticated attacker can create a usable child security association (child SA) before completing authentication, potentially allowing unauthorized access to protected traffic or resources.

Technical details

The vulnerability is an authentication bypass in libcharon's IKEv2 state machine implementation. The root cause is a missing state check when processing CREATE_CHILD_SA requests on unestablished IKE SAs: the state validation only applies when no passive tasks are queued, but when EAP authentication is used, passive tasks remain queued during authentication, allowing the check to be bypassed. An unauthenticated peer can send a CREATE_CHILD_SA request during IKE SA initiation to create a usable child SA before authentication completes. The attack requires either that the responder does not configure an IP address pool or uses explicit remote traffic selectors. The vulnerability affects strongSwan 5.9.7 through 6.0.7 and is fixed in 6.1.0.

Affected products

  • strongSwan strongSwan 5.9.7 through 6.0.7

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in strongSwan 6.1.0

References

Related threats