CVE-2026-53762
Last modified
CVE-2026-53762 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header key derivation through derive_key_sha256 and derive_key_sha512 in src/Crypto/wolfCrypt.c, where the configured iterations value is discarded and wc_HKDF is used instead of PBKDF2-HMAC. EPSS estimates a 0.06% chance of exploitation in the next 30 days.
Description
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header key derivation through derive_key_sha256 and derive_key_sha512 in src/Crypto/wolfCrypt.c, where the configured iterations value is discarded and wc_HKDF is used instead of PBKDF2-HMAC. Changing the PIM or iteration count therefore does not increase derivation cost, allowing an attacker with an affected container, disk image, or volume header to perform substantially cheaper offline password guesses. Official precompiled VeraCrypt binaries and normal distribution packages use the standard PBKDF2 backend and are not affected. Volumes created by an affected WOLFCRYPT=1 build require backup and recreation because corrected builds derive different keys. This issue is fixed in version 1.26.29.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| veracrypt | VeraCrypt | < 1.26.29 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53762?
How severe is CVE-2026-53762?
How do I fix CVE-2026-53762?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53757Emlog is an open source website building system. In versions…6.9
- CVE-2026-53758Emlog is an open source website building system. In versions…8.7
- CVE-2026-53759linuxfabrik-lib provides Python modules for database access,…2
- CVE-2026-5376An issue that could prevent session inactivity timeouts from…5.9
- CVE-2026-53760Admidio is an open-source user management solution. In versi…5.2
- CVE-2026-53761Frappe CRM is an open-source customer relationship managemen…8.2
- CVE-2026-53763OP-TEE is a Trusted Execution Environment (TEE) designed as …3.8
- CVE-2026-53765Chrome DevTools for agents (chrome-devtools-mcp) lets your c…6.1
- CVE-2026-53766Chrome DevTools for agents (chrome-devtools-mcp) lets your c…6.1
- CVE-2026-53769Avo is a framework to create admin panels for Ruby on Rails …6.5
- CVE-2026-5377GitLab has remediated an issue in GitLab CE/EE affecting all…4.3
- CVE-2026-53776Perry before 0.5.1166 contains a JWT validation vulnerabilit…9.3
Are you affected by CVE-2026-53762?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
