PT-2026-82592 · Unknown · Openssl-Encrypt

CVE-2026-81691

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software fails to validate server URLs within the login() and register with email() functions, allowing the use of unconfigured hosts and unencrypted http:// URLs. This allows attackers positioned on the network path to intercept cleartext credentials, such as client id, passwords, and JWTs (JSON Web Tokens, which are compact, URL-safe means of representing claims to be transferred between two parties), leading to a full keyserver account takeover.
Recommendations Update to version 1.4.9 or later. As a temporary workaround, avoid using the login() and register with email() functions with unencrypted http:// URLs.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81691
GHSA-XR64-HCXG-4GHR
PYSEC-2026-3797

Affected Products

Openssl-Encrypt