CVE-2026-25998Disclosure(strongswan / strongman)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key stream is generated to encrypt the data in the database fields. But because strongMan did not generate individual IVs, every database field was encrypted using the same key stream. An attacker that has access to the database can use this to recover the encrypted credentials. In particular, because certificates, which have to be considered public information, are also encrypted using the same mechanism, an attacker can directly recover a large chunk of the key stream, which allows them to decrypt basically all other secrets especially ECDSA private keys and EAP secrets, which are usually a lot shorter. Version 0.2.0 fixes the issue by switching to AES-GCM-SIV encryption with a random nonce and an individually derived encryption key, using HKDF, for each encrypted value. Database migrations are provided to automatically re-encrypt all credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-323CWE-1204

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strongman

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
strongman

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-20: 102-1802-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Trail of Bits@trailofbits
    Disclosure

    We traced this downstream to strongMan (CVE-2026-25998), a VPN management tool that stored encrypted private keys this way. An attacker with the SQLite file could recover every certificate and impersonate any user.

    Post summary

    The post details a vulnerability (CVE‑2026‑25998) in strongMan where encrypted private keys are stored insecurely, allowing an attacker with the SQLite file to recover all certificates and impersonate users.

    3304443.8K
    36.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25998 Cryptographic Weakness in strongMan VPN Management Interface Enables Credential Decryption https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25998

    Post summary

    The post announces a cryptographic weakness in the strongMan VPN Management Interface that allows credential decryption. No evidence of exploitation or mitigation steps is provided.

    0001047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrongswanstrongman0.1.0python-

Explore more