PT-2026-82602 · Pypi · Openssl-Encrypt

CVE-2026-81701

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software uses a denylist to identify trusted built-in plugins, which allows unsigned plugins located in top-level plugins/ directories and unknown subdirectories to bypass signature verification. This flaw enables attackers to place malicious unsigned plugins in documented installation paths to achieve arbitrary code execution within the CLI process, potentially granting access to passwords and cryptographic keys.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81701
GHSA-WXX9-P55F-WM34
PYSEC-2026-3778

Affected Products

Openssl-Encrypt