CVE-2026-78807

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

  • Published Sep 11, 2026
  • CVSS 7.1 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

CVE-2026-78807 at the National Vulnerability Database