PT-2026-82612 · Unknown · Openssl-Encrypt

CVE-2026-81717

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions openssl-encrypt versions prior to 1.4.9
Description The portable USB drive feature contains two weaknesses when the removable drive is treated as untrusted. First, the verify integrity file() function in USBDriveCreator only validates files listed in the manifest, allowing additional files, such as root-level autorun payloads, to remain undetected while integrity verification still passes. Second, a globally constant, source-embedded KDF salt LEGACY FIXED SALT is used to derive the drive encryption key for any drive lacking a per-drive salt file. This removes precomputation resistance and enables offline rainbow-table attacks, which use precomputed hashes to quickly recover passwords.
Recommendations Update openssl-encrypt to version 1.4.9 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81717
GHSA-8JX3-27QF-3P97
PYSEC-2026-3801

Affected Products

Openssl-Encrypt