Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-81680: jahlives/openssl_encrypt allows removal of recovery data
CVE-2026-81680 · published 1 month ago
Summary
Versions of jahlives/openssl_encrypt before 1.4.9 do not properly check for recovery information in encrypted files. An attacker could edit the file header to delete recovery‑slot details, removing the owner's backup path without re‑encrypting the data. Update to version 1.4.9 or later to ensure the recovery information is validated.
What to do
- Update jahlives openssl_encrypt to version 1.4.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
Original advisory text
openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81680... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-81680 Vendor Advisory
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-grhj-cpmg-f... Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-authentication... Third Party Advisory
Severity
9.3
Critical
CVSS 3.1: 4.0 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Track software like this
Free during beta