PT-2026-82607 · Unknown · Openssl-Encrypt

CVE-2026-81706

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software fails to prevent namespace collisions between own identities and contacts within the IdentityStore. This allows attackers to create shadowed contact entries that remain invisible as long as the corresponding own identity exists. Once the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, which enables silent key substitution for encrypted files.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81706
GHSA-8GMX-W9M8-VX7Q
PYSEC-2026-3781

Affected Products

Openssl-Encrypt