PT-2026-82610 · Unknown · Openssl-Encrypt

CVE-2026-81715

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl-encrypt versions prior to 1.4.9
Description The sanitize argv for debug function fails to sanitize the keyserver bearer token when passed as a positional argument to the 'keyserver set-token' command. Consequently, when the --debug flag is used, the token is printed in cleartext to stderr, regardless of the --unsafe-show-secrets setting, which can lead to the credential being stored in logs and terminal history.
Recommendations Update to version 1.4.9.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81715
GHSA-JQQP-PF9J-889J
PYSEC-2026-3964

Affected Products

Openssl-Encrypt