CVE-2026-89422
Raw vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.
Summary
CVE-2026-89422 is a critical-severity Key Exchange without Entity Authentication (CWE-322) vulnerability in Erlef (inferred from references). Its CVSS base score is 9.3 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Adversary-in-the-Middle (T1557); ranked at the 31th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-3 (Device Identification and Authentication) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-84338
Vulnerability Data
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete…
more
the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not. This issue affects OTP from OTP 22.2 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V12.1.3
Mitigating Controls (NIST 800-53 r5) AI
Requiring unique identification and authentication of users before any privileged action stops key exchange from occurring with unauthenticated parties.
Requiring device identification and authentication before establishing connections prevents unauthenticated key exchanges with unknown devices.
Requiring identification and authentication of non-organizational users blocks key exchange with unauthenticated external actors.
Requiring proper cryptographic key establishment and management directly stops unauthenticated key-exchange implementations.
Issuing or obtaining PKI certificates under an approved policy supplies the entity authentication missing from unauthenticated key exchange.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Identity proofing and binding directly supports verifying actors before key exchange.
Requiring authentication of services/hardware prevents unauthenticated key exchange.
Verifying identity assertions mitigates the missing entity authentication in key exchange.
Protecting data-in-transit implies use of authenticated key exchange but does not explicitly require entity authentication.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Identity management provides the verified identities required before key exchange occurs.
Network security policies can require authenticated channels, indirectly reducing the risk of unauthenticated key exchange.
Security of network services includes requirements for authenticated key exchange in service protocols.
Use of cryptography mandates authenticated key-exchange mechanisms, directly addressing the lack of entity authentication.
Application security requirements can mandate authenticated key exchange for any cryptographic operations.
Secure system architecture principles include authenticated key exchange as a foundational design requirement.