Padding Oracle Attack Vulnerability in Oberon PSA Crypto Library
CVE-2026-16459

5.9MEDIUM

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-16459?

A padding oracle attack vulnerability exists in Oberon microsystem AG’s Oberon PSA Crypto library, affecting all versions from 1.0.0 up to, but not including, 2.1.1. This vulnerability allows attackers to exploit timing discrepancies during RSA PKCS#1 v1.5 decryption operations, enabling them to recover plaintext data. Attackers can leverage this flaw to compromise sensitive information processed by the library.

Affected Version(s)

Oberon PSA Crypto 1.0.0 < 2.1.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.