PT-2026-82608 · Unknown · Openssl-Encrypt

CVE-2026-81707

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software fails to sanitize the email field of imported identity documents. This allows attackers to inject ANSI escape sequences—special codes used to control terminal formatting—to forge the fingerprint verification line shown to users. By delivering a crafted identity bundle via contact-exchange flows or keyserver responses, an attacker can manipulate terminal output to display a fraudulent fingerprint, bypassing the out-of-band verification mechanism designed to prevent key substitution attacks.
Recommendations Update openssl encrypt to version 1.4.9 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81707
GHSA-QJR2-X6MR-8XGF

Affected Products

Openssl-Encrypt