CVE-2026-5500 | wolfSSL up to 5.9.0 Authentication Tag wc_PKCS7_DecodeAuthEnvelopedData mac channel accessible (Nessus ID 305891)
A vulnerability classified as problematic was found in wolfSSL up to 5.9.0. Affected by this issue is the function wc_PKCS7_DecodeAuthEnvelopedData of the component Authentication Tag Handler. Such manipulation of the argument mac leads to channel accessible by non-endpoint.
This vulnerability is referenced as CVE-2026-5500. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.