CVE-2026-107785
Last modified
CVE-2026-107785 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires.
Description
Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted. For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the "Enforce SKA Use" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer's traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Sirius Computer, Inc. | Crux Agent | >= 1.9.0, < 2.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107785?
How severe is CVE-2026-107785?
How do I fix CVE-2026-107785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107778MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer…6.5
- CVE-2026-107779Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e…9.8
- CVE-2026-107780Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e…9.8
- CVE-2026-107781Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e…7.4
- CVE-2026-107782System Informer before 4.0.26241.138 contains an incorrect a…7.8
- CVE-2026-107783Insertion of sensitive information into log file in AWS Tool…5.9
- CVE-2026-10779The Classified Listing – Classified ads & Business Directory…4.3
- CVE-2026-107792Jivejdon from commit d58a36b0 through commit ee67a65e contai…4.3
- CVE-2026-107793Jivejdon through 5.0 contains an authorization bypass vulner…4.3
- CVE-2026-107796Jivejdon from commit 5489372d through commit ee67a65e contai…6.1
- CVE-2026-107797Jivejdon through 5.0 contains a reflected cross-site scripti…6.1
- CVE-2026-107798jivejdon from commit 595d8d22 through commit ee67a65e contai…5.4
Are you affected by CVE-2026-107785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
