CVE-2026-93302
wolfssl wolfssl
Summary
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is also defined this widens the affected API to include all CA certificate loading. Both macros are defined when using autoconf builds such as (nginx, haproxy, stunnel, wpas, apache httpd, hitch, bind, rsyslog, ffmpeg, all, distro). When the certificate is listed as a trusted peer certificate the issue previously allowed for a malicious (D)TLS server to bypass authentication once knowing which CA’s the client would accept. This also affects mutual authentication cases where the client knows which CA’s the server has loaded. If building with any of these configurations and using (D)TLS where the loaded CA’s could be known and authentication of the peer is desired, users should either: update to the latest wolfSSL version, apply the fix patch, or use the configure flag --disable-openssl-compatible-defaults and not load CA’s with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert() to mitigate the issue.
Published 2026-09-27 · first seen here 2026-10-10
Analysis & write-ups
No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.
Where it shows in your logs
Server or web application · Authentication bypass or missing authorisation low confidence
What to look for
- Admin or API actions with no successful login before them in the same session
- New admin accounts, API keys or tokens created shortly after unusual requests
- Requests to admin or API endpoints from internet IPs
- The application's process (w3wp.exe, java, tomcat, node, php-fpm, httpd, python) starting shells or LOLBins (cmd, powershell, sh, bash, curl, wget, certutil)
- New script files in web roots (.jsp, .aspx, .php): a web shell
- Requests to unusual URLs on the application from internet IPs right before any of the above
- Outbound connections from the server to new external IPs
Data sources
Web server and WAF logs · ATT&CK DS0015 Application Log Content
- Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession- Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes- CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs
Process creation · ATT&CK DS0009 Process Creation
- Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate- Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)- CrowdStrike
ProcessRollup2SyntheticProcessRollup2
File creation · ATT&CK DS0022 File Creation
- Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent- Splunk
Endpoint.FilesystemSysmon Event ID 11- CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events
Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow
- Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession- Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)- CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6
Authentication and sessions · ATT&CK DS0028 Logon Session Creation / DS0002 User Account Authentication
- Sentinel
SigninLogsSecurityEvent (4624, 4625, 4648)DeviceLogonEventsIdentityLogonEvents_Im_Authentication- Splunk
Authentication.Authenticationpan:globalprotectVPN sourcetypes- CrowdStrike
UserLogonUserLogonFailed2Falcon Identity Protection events
Account and group changes · ATT&CK DS0002 User Account Creation / Modification
- Sentinel
SecurityEvent (4720, 4728, 4732, 4756)AuditLogsIdentityDirectoryEvents- Splunk
Change.All_Changes (Account_Management)WinEventLog:Security (4720, 4732)- CrowdStrike
UserAccountCreatedUserAccountAddedToGroup
A generic baseline worked out from the product type and weakness (CWE-295), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.