PT-2026-82589 · Pypi · Openssl-Encrypt

CVE-2026-81688

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software stores an unkeyed SHA-256 hash of the plaintext within the cleartext file header metadata. This allows attackers to read the hash without requiring a password, enabling them to confirm guessed plaintexts offline or identify identical plaintexts across different encrypted files.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81688
GHSA-7C3Q-GP4V-Q29Q
PYSEC-2026-3795

Affected Products

Openssl-Encrypt