PT-2026-82595 · Unknown · Openssl-Encrypt

CVE-2026-81694

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions openssl-encrypt versions prior to 1.4.9
Description The software fails to sanitize filenames read from untrusted drive data located outside the AES-GCM authenticated manifest before displaying them in the output of the verify-usb command. An attacker can use filenames containing terminal cursor-movement and erase-line control bytes to repaint a forged PASSED verdict on the screen, which masks actual tamper detection.
Recommendations Update to version 1.4.9.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81694
GHSA-C793-RJ9W-R3WG
PYSEC-2026-3960

Affected Products

Openssl-Encrypt