PT-2026-82592 · Unknown · Openssl-Encrypt
CVE-2026-81691
·
Published
2026-08-27
·
Updated
2026-08-31
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.9
Description
The software fails to validate server URLs within the
login() and register with email() functions, allowing the use of unconfigured hosts and unencrypted http:// URLs. This allows attackers positioned on the network path to intercept cleartext credentials, such as client id, passwords, and JWTs (JSON Web Tokens, which are compact, URL-safe means of representing claims to be transferred between two parties), leading to a full keyserver account takeover.Recommendations
Update to version 1.4.9 or later.
As a temporary workaround, avoid using the
login() and register with email() functions with unencrypted http:// URLs.Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt