{"id":"CVE-2026-78807","title":"An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c","summary":"An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-346","CWE-322"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9"],"published":"2026-09-11","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:56:19.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78807","references":[{"url":"https://w1.fi/security/2026-2/missing-network-context-validation-for-pmksa-caching.txt","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78807.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-78807"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531997"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78807"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78807"}],"tags":["nvd","csaf","vex","red-hat","cve.org"],"epss":0.0008,"epssPercentile":0.00218,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T20:10:48.208026Z"},"ingestedAt":"2026-09-14T10:09:58.905Z","slug":"CVE-2026-78807","body":"## Overview\n\nAn issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78807.json)","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}