Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added. | |
| Title | openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:50:46.683Z
Reserved: 2026-08-27T11:11:30.933Z
Link: CVE-2026-81680
No data.
Status : Received
Published: 2026-08-27T17:20:57.300
Modified: 2026-08-27T17:20:57.300
Link: CVE-2026-81680
No data.
OpenCVE Enrichment
No data.