PT-2026-82587 · Unknown · Openssl-Encrypt

CVE-2026-81686

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions 1.4.x through 1.4.8
Description An optional D-Bus crypto service contains a flaw where the 'org.freedesktop.DBus.Properties.Set' method lacks polkit authorization checks and value validation. A local user on the system bus can call this method without authorization to modify the MaxConcurrentOperations variable (setting it to 0, a negative value, or an excessively large value) or the DefaultTimeout variable. These actions can cause the concurrency gate to refuse operations or remove limits, leading to a persistent denial of service of the root daemon.
Recommendations Update openssl encrypt to version 1.4.9 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81686
GHSA-7FHX-8RMV-QJJ3
PYSEC-2026-3794

Affected Products

Openssl-Encrypt