PT-2026-48875 · Veracrypt · Veracrypt

CVE-2026-54073

·

Published

2026-06-12

·

Updated

2026-08-21

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions VeraCrypt versions 1.26.6 through 1.26.28
Description File-hosted hidden volume creation forces a quick format where the FormatNoFs() function in src/Common/Format.c and FormatFat() function in src/Common/Fat.c use WriteFile to place raw zeroed sectors at predictable 128 MiB intervals. These writes bypass the normal EncryptDataUnits formatting path, resulting in deterministic plaintext markers in areas that should appear as random ciphertext. This behavior weakens plausible deniability during forensic inspection, although it does not expose the content of the hidden volume or compromise the encryption strength.
Recommendations Update to version 1.26.29, recreate the container and hidden volume using the updated version, and securely erase the old one.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54073
GHSA-JJCR-75W7-58JP

Affected Products

Veracrypt