Description
Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.
Published: 2026-10-02
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Plaintext recovery via padding oracle
Action: Patch immediately
AI Analysis

Impact

The vulnerability in the IesEngine implementation allows a remote attacker who has captured an IES or ECIES ciphertext to recover its plaintext through a CBC padding‑oracle attack. The engine decrypts the ciphertext and removes the padding before verifying the MAC, which means a padding failure is reported with a different error message than a MAC failure, leaking information about the plaintext. This flaw is a classic information‑exposure weakness (CWE-203).

Affected Systems

Applications using the Bouncy Castle bc-csharp library prior to version 2.7.0 are affected. The flaw only manifests when IesEngine is constructed with a padded block‑cipher mode such as AES in CBC mode with PKCS#7 padding. Stream‑mode IES is not impacted.

Risk and Exploitability

The CVSS score of 8.2 classifies the issue as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the attack requires only the submission of modified ciphertexts under the same key pair, making it feasible for a remote attacker. The impact could be significant if sensitive data are encrypted with susceptible configurations.

Generated by OpenCVE AI on October 2, 2026 at 09:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Bouncy Castle bc‑csharp to version 2.7.0 or later.
  • If an update is not possible, avoid using block‑cipher modes with PKCS#7 padding in IesEngine.
  • Ensure that any application logic performs MAC verification before padding removal to mitigate the padding‑oracle behavior.

Generated by OpenCVE AI on October 2, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.
Title IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T06:58:32.487Z

Reserved: 2026-07-16T23:48:46.076Z

Link: CVE-2026-63567

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T07:16:37.127

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses