A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-5466

CVE-2026-5466: WolfSSL Auth Bypass Vulnerability

CVE-2026-5466 is an authentication bypass flaw in WolfSSL's ECCSI signature verifier that allows attackers to forge signatures for any message or identity. This article covers technical details, affected versions, and mitigation.

Updated: May 14, 2026

CVE-2026-5466 Overview

CVE-2026-5466 is a cryptographic signature verification flaw in wolfSSL's Elliptic Curve-based Certificateless Signatures for Identity-based Encryption (ECCSI) implementation. The verifier function wc_VerifyEccsiHash decodes the r and s scalars from a signature blob using mp_read_unsigned_bin without validating that the values lie within the cryptographically required range [1, q-1]. An attacker can forge a signature that verifies against any message for any identity using only publicly-known constants. The flaw is tracked under CWE-347: Improper Verification of Cryptographic Signature and affects the wolfSSL embedded TLS library.

Critical Impact

Forged ECCSI signatures verify as valid against any message and any identity, fully breaking signature authenticity guarantees.

Affected Products

  • wolfSSL embedded TLS library (ECCSI signature verification path)
  • Applications and devices relying on wolfSSL wc_VerifyEccsiHash for identity-based signature verification
  • Embedded and IoT deployments using wolfCrypt ECCSI primitives

Discovery Timeline

  • 2026-04-10 - CVE-2026-5466 published to NVD
  • 2026-04-29 - Last updated in NVD database

Technical Details for CVE-2026-5466

Vulnerability Analysis

The Elliptic Curve-based Certificateless Signatures for Identity-based Encryption (ECCSI) scheme, defined in RFC 6507, requires the verifier to reject signature scalars that fall outside the valid range [1, q-1], where q is the curve subgroup order. wolfSSL's wc_VerifyEccsiHash implementation omits this bounds check after decoding signature components with mp_read_unsigned_bin.

This omission breaks a fundamental precondition of the ECCSI verification equation. An adversary can craft signature values that trivially satisfy the verifier's algebraic check regardless of the message content or the claimed signer identity. Because the attack requires only publicly-known curve constants and identity material, no secret key knowledge is required.

The attack vector is Adjacent Network, meaning the attacker must be able to deliver a forged signature to a vulnerable verifier within the same logical network segment or protocol session.

Root Cause

The root cause is missing input validation on cryptographic scalars during signature parsing. mp_read_unsigned_bin converts raw bytes into multi-precision integer form but performs no range or zero-value checks. The verifier proceeds to use these unvalidated scalars in elliptic curve point multiplications, producing a verification equation that an attacker can satisfy with degenerate values.

Attack Vector

An attacker constructs a signature blob containing r and s scalars chosen to bypass the verification equation. The forged signature is then submitted to any application that authenticates messages or identities through wc_VerifyEccsiHash. Because verification succeeds, the attacker can impersonate arbitrary identities and authenticate arbitrary messages, undermining the entire ECCSI authentication model.

No verified public exploit code is currently available. Technical details of the fix are described in the wolfSSL Pull Request #10102, which adds the missing scalar range validation.

Detection Methods for CVE-2026-5466

Indicators of Compromise

  • Successful ECCSI signature verifications associated with identities or messages that were never legitimately signed by an authorized signer.
  • Signature blobs containing r or s scalar values equal to zero or greater than or equal to the curve subgroup order q.
  • Anomalous authentication events on embedded devices using wolfSSL where signing key custody cannot account for the verified message.

Detection Strategies

  • Inventory all binaries and firmware images linking against wolfSSL and identify versions predating the fix in PR #10102.
  • Instrument or log calls to wc_VerifyEccsiHash to capture scalar values and flag signatures where r or s is zero or out of range.
  • Compare verification outcomes against an independent ECCSI verifier that enforces RFC 6507 range checks to detect divergent results.

Monitoring Recommendations

  • Audit application logs for authentication anomalies tied to ECCSI-protected protocols, particularly repeated successful verifications from unexpected peers.
  • Monitor adjacent network segments hosting wolfSSL-based identity verification endpoints for unsolicited signature submissions.
  • Track wolfSSL upstream advisories and version metadata across embedded fleets to confirm patch coverage.

How to Mitigate CVE-2026-5466

Immediate Actions Required

  • Upgrade wolfSSL to a release containing the fix from PR #10102 across all affected products and firmware images.
  • Identify systems exposing wc_VerifyEccsiHash to untrusted or adjacent-network peers and prioritize them for patching.
  • Treat any ECCSI-authenticated decisions made by unpatched verifiers as untrusted until validation is reperformed with a fixed build.

Patch Information

The upstream fix adds explicit range validation on the decoded r and s scalars to ensure each lies within [1, q-1] before the verification equation is evaluated. Apply the patch by upgrading to a wolfSSL release that incorporates Pull Request #10102 and rebuilding dependent applications and firmware.

Workarounds

  • Disable ECCSI signature verification code paths if the feature is not required by the application or protocol stack.
  • Restrict access to verifier endpoints using network segmentation so that only trusted adjacent peers can submit signatures.
  • Layer an additional signature verification mechanism, such as ECDSA over a separately authenticated channel, until the wolfSSL update is deployed.
bash
# Configuration example: rebuild wolfSSL without ECCSI support as a temporary workaround
./configure --disable-eccsi
make && sudo make install

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechWolfssl

  • SeverityHIGH

  • CVSS Score7.6

  • EPSS Probability0.01%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-347
  • Technical References
  • GitHub Pull Request for wolfSSL
  • Related CVEs
  • CVE-2026-2645: wolfSSL TLS Auth Bypass Vulnerability

  • CVE-2025-15346: wolfSSL-py mTLS Auth Bypass Vulnerability

  • CVE-2026-5501: WolfSSL Information Disclosure Flaw

  • CVE-2026-5448: wolfSSL X.509 Buffer Overflow Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English