PT-2026-82606 · Unknown · Openssl-Encrypt

CVE-2026-81705

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl-encrypt versions prior to 1.4.9
Description The software fails to redact file passwords in the --debug argv dump when passwords are provided using bundled short-option spellings (e.g., -apHunter2) or abbreviated long-option spellings (e.g., --passw). Because the sanitizer only recognizes exact option names, --option=value formats, and tokens starting with -p, these specific spellings bypass the redaction process. Consequently, the cleartext password is written to stderr, allowing anyone with access to terminal scrollback, merged output, CI job logs, or persistent debug logs to recover the password.
Recommendations Update openssl-encrypt to version 1.4.9 or later.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81705
GHSA-JGVM-7JXV-CGCC
PYSEC-2026-3780

Affected Products

Openssl-Encrypt