PT-2026-82581 · Unknown · Openssl-Encrypt

CVE-2026-81680

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description Failure to authenticate the presence of recovery slots in envelope-format encrypted files allows attackers to remove these slots without re-encrypting the payload. By modifying the file header to delete recovery-slot fields, an attacker can bypass authentication and silently remove recovery paths intentionally added by the owner.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81680
GHSA-GRHJ-CPMG-F5MX
PYSEC-2026-3957

Affected Products

Openssl-Encrypt