Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-81685: openssl_encrypt before 1.4.9 can show fake delete warnings

CVE-2026-81685 · published 1 month ago
Summary

Versions of openssl_encrypt older than 1.4.9 do not clean up certain data in the desktop interface, so a crafted encrypted file can make the confirmation dialog display misleading text. This could cause users to delete or keep files based on false information. Upgrade to version 1.4.9 or later to resolve the issue.

What to do
  • Update jahlives openssl_encrypt to version 1.4.9 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.9
Original advisory text
openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata
openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot identifiers containing bidi overrides or line-separator characters to forge warning text and deceive users during file removal operations.
Severity
9.3 Critical
CVSS 3.1: 3.3 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-116Improper Encoding or Escaping of Output
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-81685 · MITRE
Track software like this
Free during beta