Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5504

21
FAUCET Score

OVERVIEW CVE-2026-5504 is a padding oracle vulnerability in wolfSSL's PKCS7 CBC decryption implementation. The flaw exists because interior padding bytes are not properly validated during decryption operations, allowing attackers to recover plaintext data through repeated decryption queries with modified ciphertext. SEVERITY The vulnerability requires an attacker to have direct access to perform repeated decryption queries against the affected system, indicating an attack complexity that is not trivial. While specific CVSS metrics are not available, the EPSS score of 0.00025 indicates this vulnerability has exceptionally low predicted exploitation probability. The potential impact is confidentiality breach through plaintext recovery, though the practical risk appears limited by access requirements and exploitation difficulty. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. The FAUCET Risk Score of 35.0 out of 100 further suggests low current threat activity. The vulnerability remains inactive on security hotlists, and no public exploit code availability has been reported, indicating minimal community attention to date.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 5.9.0CPE match
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
<= 5.9.0CPE matchmatch criteria
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 0th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-5504Moderate

PKCS7 CBC Padding Oracle — Plaintext Recovery

Apr 14, 2026

References

github.com / wolfSSL/wolfssl/pull/10088
Issue TrackingPatch