CVE-2026-107785
Received Received - Intake

WireGuard Key Size Validation Flaw in Crux Agent

Vulnerability report for CVE-2026-107785, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: d0a6edd6-4b7d-45f2-a6f9-9b944f7b6132

Description

Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted. For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the "Enforce SKA Use" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer's traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Sirius Computer, Inc. Crux Agent 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-394 The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
CWE-252 The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
CWE-325 The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Crux Agent versions 1.9.0 to 2.0.3 use an invalid WireGuard preshared key when negotiating SHA-512 sessions. The key becomes 64 bytes instead of the required 32 bytes, causing tunnel updates to fail. This leaves the tunnel using its previous key until shutdown, preventing restarts.

Detection Guidance

Check WireGuard tunnel configurations for invalid preshared keys by inspecting the configuration files and running 'wg show' to verify key sizes. Look for tunnels with keys exceeding 32 bytes or missing preshared keys when 'Enforce SKA Use' is disabled.

Impact Analysis

If the tunnel fails to start after a restart, network connectivity may be disrupted. For peers without a 32-byte key and with 'Enforce SKA Use' disabled, no preshared key is set, allowing potential decryption by attackers with quantum computing access.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA due to potential unauthorized decryption of intercepted traffic. GDPR requires protection of personal data, and HIPAA mandates safeguarding protected health information. The flaw allows attackers with quantum computing access to decrypt stored traffic, violating confidentiality requirements.

Mitigation Strategies

Upgrade Crux Agent to version 2.0.3 or later. Verify WireGuard tunnel configurations have valid 32-byte preshared keys. If 'Enforce SKA Use' is disabled, ensure preshared keys are properly set to prevent decryption risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107785. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart