← Terug naar overzicht

CVE-2026-81701 affects openssl_encrypt versions prior to 1.4.9, which use a denylist approach to identify trusted built-in plugins rather than a more secure allowlist. This design flaw allows unsigned plugins placed in top-level plugins/ directories or unknown subdirectories to bypass signature verification entirely. Attackers who can place malicious unsigned plugins along documented installation paths can achieve arbitrary code execution within the CLI process. The impact is severe as the compromised process has direct access to passwords and cryptographic keys. The vulnerability is fixed in version 1.4.9 of openssl_encrypt. Security advisories have been published on GitHub and VulnCheck detailing the issue and remediation steps.

Affected products

  • openssl_encrypt

Related CVE's

  • CVE-2026-81701

Categories

  • Security Tools
  • Supply Chain & Dependencies
  • Zero-Day Vulnerabilities