PT-2026-82613 · Unknown · Openssl-Encrypt

CVE-2026-81718

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software uses under-parameterized PBKDF2-HMAC-SHA256, a key derivation function, with insufficient iteration counts: 100,000 iterations for protecting PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. This allows attackers who obtain keyfiles or encrypted files to perform offline brute-force attacks on wrapping passwords using GPU or ASIC acceleration.
Recommendations Update openssl encrypt to version 1.4.9 or later.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81718
GHSA-FMJX-P826-6FVR

Affected Products

Openssl-Encrypt