Cyber Resilience

CVE-2026-89422

Published
22 September 2026
Modified
22 September 2026
CVSS Score v4 9.3
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0037 31th percentile
Risk Priority 45 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2026-89422 is a critical-severity Key Exchange without Entity Authentication (CWE-322) vulnerability in Erlef (inferred from references). Its CVSS base score is 9.3 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Adversary-in-the-Middle (T1557); ranked at the 31th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-3 (Device Identification and Authentication) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete…

more

the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not. This issue affects OTP from OTP 22.2 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1557 Adversary-in-the-Middle Credential Access
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2024-4871Shared CWE-322
CVE-2026-1354Shared CWE-322
CVE-2026-58065Shared CWE-322
CVE-2025-62501Shared CWE-322
CVE-2025-20163Shared CWE-322
CVE-2025-10966Shared CWE-322
CVE-2026-11745Shared CWE-322
CVE-2026-1709Shared CWE-322
CVE-2024-47519Shared CWE-322
CVE-2025-13914Shared CWE-322

Affected Assets

Erlef
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V12.1.3

Mitigating Controls (NIST 800-53 r5) AI

Requiring unique identification and authentication of users before any privileged action stops key exchange from occurring with unauthenticated parties.

Requiring device identification and authentication before establishing connections prevents unauthenticated key exchanges with unknown devices.

Requiring identification and authentication of non-organizational users blocks key exchange with unauthenticated external actors.

Requiring proper cryptographic key establishment and management directly stops unauthenticated key-exchange implementations.

Issuing or obtaining PKI certificates under an approved policy supplies the entity authentication missing from unauthenticated key exchange.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-02 partial match
prevents

Identity proofing and binding directly supports verifying actors before key exchange.

PR.AA-03 partial match
prevents

Requiring authentication of services/hardware prevents unauthenticated key exchange.

PR.AA-04 partial match
prevents

Verifying identity assertions mitigates the missing entity authentication in key exchange.

PR.DS-02 partial match
prevents

Protecting data-in-transit implies use of authenticated key exchange but does not explicitly require entity authentication.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Identity management provides the verified identities required before key exchange occurs.

mitigates

Network security policies can require authenticated channels, indirectly reducing the risk of unauthenticated key exchange.

mitigates

Security of network services includes requirements for authenticated key exchange in service protocols.

prevents

Use of cryptography mandates authenticated key-exchange mechanisms, directly addressing the lack of entity authentication.

prevents

Application security requirements can mandate authenticated key exchange for any cryptographic operations.

prevents

Secure system architecture principles include authenticated key exchange as a foundational design requirement.

References