PT-2026-82608 · Unknown · Openssl-Encrypt
CVE-2026-81707
·
Published
2026-08-27
·
Updated
2026-08-31
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.9
Description
The software fails to sanitize the email field of imported identity documents. This allows attackers to inject ANSI escape sequences—special codes used to control terminal formatting—to forge the fingerprint verification line shown to users. By delivering a crafted identity bundle via contact-exchange flows or keyserver responses, an attacker can manipulate terminal output to display a fraudulent fingerprint, bypassing the out-of-band verification mechanism designed to prevent key substitution attacks.
Recommendations
Update openssl encrypt to version 1.4.9 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt