PT-2026-82581 · Unknown · Openssl-Encrypt
CVE-2026-81680
·
Published
2026-08-27
·
Updated
2026-09-03
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.9
Description
Failure to authenticate the presence of recovery slots in envelope-format encrypted files allows attackers to remove these slots without re-encrypting the payload. By modifying the file header to delete recovery-slot fields, an attacker can bypass authentication and silently remove recovery paths intentionally added by the owner.
Recommendations
Update to version 1.4.9 or later.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt