PT-2026-82614 · Unknown · Openssl-Encrypt

CVE-2026-81719

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description Insufficient controls during the execution of untrusted third-party plugins allow for arbitrary code execution with the privileges of the user running the software. This occurs because the plugin signature policy defaults to WARN, enabling the compilation and execution of unsigned or unverifiable non-built-in plugins within the host process at import time, before the runtime sandbox is active. The existing protection relied on an incomplete and bypassable AST (Abstract Syntax Tree) denylist, which is a list of forbidden code patterns used to block malicious syntax.
Recommendations Update to version 1.4.9.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81719
GHSA-587J-4R3V-CM2C
PYSEC-2026-3802

Affected Products

Openssl-Encrypt