PT-2026-82587 · Unknown · Openssl-Encrypt
CVE-2026-81686
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions 1.4.x through 1.4.8
Description
An optional D-Bus crypto service contains a flaw where the 'org.freedesktop.DBus.Properties.Set' method lacks polkit authorization checks and value validation. A local user on the system bus can call this method without authorization to modify the
MaxConcurrentOperations variable (setting it to 0, a negative value, or an excessively large value) or the DefaultTimeout variable. These actions can cause the concurrency gate to refuse operations or remove limits, leading to a persistent denial of service of the root daemon.Recommendations
Update openssl encrypt to version 1.4.9 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt