CVE-2026-78807: Linux wpa_supplicant vulnerability
Published Sep 11, 2026
·Updated
An issue in wpasupplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
Affected Software
1 affected component
Linux wpa_supplicant<2.12
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wpa_supplicantto a version that resolves this vulnerability.Fixed in 2.12
Event History
Sep 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
How can I determine whether a system is affected?
Linux systems running wpa_supplicant versions earlier than 2.12 are affected. Systems running version 2.12 or later are not identified as affected by the provided information.
2
What level of access does an attacker need?
Exploitation requires a local attacker. The issue involves the driver-based PMKSA selection path, so environments using that path should be prioritized for review.