Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offline password guessing at hardware speed to recover user passwords. | |
| Title | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation | |
| Weaknesses | CWE-916 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:50:54.590Z
Reserved: 2026-08-27T11:12:00.889Z
Link: CVE-2026-81689
No data.
Status : Received
Published: 2026-08-27T17:20:58.697
Modified: 2026-08-27T17:20:58.697
Link: CVE-2026-81689
No data.
OpenCVE Enrichment
No data.