PT-2026-82611 · Unknown · Openssl-Encrypt

CVE-2026-81716

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description A path traversal flaw exists in the PluginSandbox. is safe path() function. The issue occurs because file access is authorized using a bare string-prefix match. This allows a sandboxed plugin lacking the READ FILES permission to read or write directories of other plugins that share a similar name prefix, which compromises the isolation between plugins for the same user.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81716
GHSA-VR4H-5XQV-XXXF
PYSEC-2026-3800

Affected Products

Openssl-Encrypt