CVE-2026-21094: Input Validation
Published Sep 9, 2026
·Updated
Improper input validation in wpasupplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.
Affected Software
1 affected component
OpenBSD wpa_supplicant<SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to exploitation?
Systems using the identified OpenBSD wpa_supplicant software before SMR Sep-2026 Release 1 are in scope. The attacker must be adjacent to the target.
2
What access does an attacker need?
The available information identifies this as an adjacent-attacker issue. It does not state that exploitation can be performed by an attacker without adjacency.
3
How can I determine whether my deployment is affected?
Check whether the wpa_supplicant version predates SMR Sep-2026 Release 1. The provided data does not include additional configuration-based indicators or detection methods.