AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16458

MEDIUM · CVSS 5.9 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A padding oracle attack vulnerability exists in the ocrypto library used by Oracle, affecting all versions from 3.0.0 to prior to 4.0.1. This flaw allows attackers to exploit timing discrepancies during RSA PKCS#1 v1.5 decryption operations to recover plaintext data. Organizations utilizing affected versions of the ocrypto library should prioritize remediation to mitigate the risk of data exposure.

CVE
CVE-2026-16458
Severity
MEDIUM
CVSS
5.9
EPSS
0.07%
Oracle

Original NVD Description

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.