Padding Oracle Attack in Oberon Microsystem AG’s Ocrypto Library
CVE-2026-16458

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-16458?

A vulnerability has been identified in the Ocrypto library developed by Oberon microsystem AG, which affects all versions from 3.0.0 to prior 4.0.1. This issue arises from a padding oracle attack that enables an unauthorized actor to potentially recover plaintexts by analyzing timing variations of RSA PKCS#1 v1.5 decryption operations. As a result, systems utilizing this library may be at risk of data exposure, highlighting the importance of immediate updates and monitoring.

Affected Version(s)

ocrypto 3.0.0 < 4.0.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.