CVE-2026-78807: An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

Overview

Severity
High (CVSS 7.1)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploit Status
Not Exploited
Patch Tuesday
2026-Sep
Released
2026-09-21
Last Updated
2026-09-21
EPSS Score
0.08% (percentile: 0.2%)

Affected Products (1)

Other

  • 19363-17084

Security Updates (1)

Revision History

  • 2026-09-21: Information published.
  • 2026-09-21: Information published.