PT-2026-82585 · Unknown · Openssl-Encrypt
CVE-2026-81684
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
openssl-encrypt versions prior to 1.4.9
Description
The desktop GUI passes the steganography password to the CLI child process using the
--stego-password argument during both encryption and decryption processes. Because this is passed via the command line rather than an environment variable, any local user can retrieve the password by reading the /proc/<pid>/cmdline file while the subprocess is active.Recommendations
Update openssl-encrypt to version 1.4.9.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt