PT-2026-82614 · Unknown · Openssl-Encrypt
CVE-2026-81719
·
Published
2026-08-27
·
Updated
2026-08-31
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.9
Description
Insufficient controls during the execution of untrusted third-party plugins allow for arbitrary code execution with the privileges of the user running the software. This occurs because the plugin signature policy defaults to WARN, enabling the compilation and execution of unsigned or unverifiable non-built-in plugins within the host process at import time, before the runtime sandbox is active. The existing protection relied on an incomplete and bypassable AST (Abstract Syntax Tree) denylist, which is a list of forbidden code patterns used to block malicious syntax.
Recommendations
Update to version 1.4.9.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt