PT-2026-82603 · Unknown · Openssl-Encrypt

CVE-2026-81702

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software fails to re-derive and validate fingerprints when loading identities from the identity.json file. This allows attackers to substitute legitimate public keys in identity stores with their own while maintaining the claimed fingerprint. Consequently, this enables silent key substitution, resulting in encryption using attacker-controlled keys while signature verification still appears valid.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81702
GHSA-Q8P3-7H6H-GHFR
PYSEC-2026-3962

Affected Products

Openssl-Encrypt