PT-2026-83148 · Unknown · Wolfengine

CVE-2026-81341

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions wolfEngine versions prior to 1.4.1
Description wolfEngine incorrectly sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of using the TLS sequence number within the additional authenticated data. Since the record layer leaves the explicit-nonce field for the cipher to populate, the value remains constant across records. This results in every AES-CCM record within a connection being encrypted using an identical key and nonce pair. Reusing a CCM key and nonce compromises confidentiality, as an identical keystream is used across records, and weakens integrity by allowing authentication tag forgery. This issue only affects wolfEngine when AES-CCM cipher suites are explicitly selected, as they are not enabled by default.
Recommendations Update wolfEngine to version 1.4.1 or later. As a temporary mitigation, avoid explicitly selecting AES-CCM cipher suites.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81341

Affected Products

Wolfengine