PT-2026-82606 · Unknown · Openssl-Encrypt
CVE-2026-81705
·
Published
2026-08-27
·
Updated
2026-09-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openssl-encrypt versions prior to 1.4.9
Description
The software fails to redact file passwords in the
--debug argv dump when passwords are provided using bundled short-option spellings (e.g., -apHunter2) or abbreviated long-option spellings (e.g., --passw). Because the sanitizer only recognizes exact option names, --option=value formats, and tokens starting with -p, these specific spellings bypass the redaction process. Consequently, the cleartext password is written to stderr, allowing anyone with access to terminal scrollback, merged output, CI job logs, or persistent debug logs to recover the password.Recommendations
Update openssl-encrypt to version 1.4.9 or later.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt