PatchSiren

wpa_supplicant CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wpa_supplicant CVE published 2026-09-11

CVE-2026-78807

A local attacker can bypass proper network context and AKMP matching for PMKSA caching in wpa_supplicant versions before v.2.12 due to missing validation in the driver-based PMKSA selection path. This vulnerability allows for potential unauthorized access to network resources. Network administrators and security teams should verify and apply patches for versions before v.2.12, review network configuration [truncated]