PT-2026-20491 · Strongman+1 · Strongman+1

Tobiasbrunner

·

Published

2026-02-18

·

Updated

2026-02-23

·

CVE-2026-25998

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions strongMan versions prior to 0.2.0
Description strongMan, a management interface for strongSwan, improperly encrypted credentials stored in its database. The software used AES in CTR mode with a global database key and a consistent initialization vector (IV) for all database fields. This allowed an attacker with database access to recover encrypted credentials, including certificates, ECDSA private keys, and EAP secrets. Because certificates are considered public information, an attacker could recover a significant portion of the key stream, facilitating decryption of other sensitive data. The API endpoint used for credential storage was not specified. The vulnerable parameter was the database fields containing credentials (private keys, EAP secrets).
Recommendations Upgrade to strongMan version 0.2.0 or later. Run the provided database migrations to re-encrypt all credentials.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-25998
GHSA-88W4-JV97-C8XR

Affected Products

Strongman
Strongswan