SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-78807

HIGH · CVSS 7.1 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in wpa_supplicant prior to version 2.12 allows local attackers to exploit inadequate validation in the driver-based PMKSA selection process, enabling them to bypass network context and AKMP matching for PMKSA caching. This could lead to unauthorized access to secured networks, compromising the confidentiality and integrity of network communications. Organizations using affected versions of wpa_supplicant should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-78807
Severity
HIGH
CVSS
7.1
EPSS
0.08%

Original NVD Description

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c