CVE-2026-78807

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

Published 2026-09-11. Last modified 2026-09-22.