CVE-2026-81707
Last modified
CVE-2026-81707 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks..
Description
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81707?
How severe is CVE-2026-81707?
How do I fix CVE-2026-81707?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81701openssl_encrypt versions before 1.4.9 use a denylist to iden…9.8
- CVE-2026-81702openssl_encrypt before 1.4.9 fails to re-derive and validate…9.8
- CVE-2026-81703openssl_encrypt versions before 1.4.9 fail to validate encry…5.5
- CVE-2026-81704openssl_encrypt versions before 1.4.9 contain a weak key der…7.5
- CVE-2026-81705openssl-encrypt before 1.4.9 fails to redact the file passwo…7.5
- CVE-2026-81706openssl_encrypt before 1.4.9 fails to prevent namespace coll…6.8
- CVE-2026-81714openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use…7
- CVE-2026-81715openssl_encrypt (pip package openssl-encrypt) versions <= 1.…3.3
- CVE-2026-81716openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9…5.2
- CVE-2026-81717openssl_encrypt (pip package openssl-encrypt) before 1.4.9 c…3.5
- CVE-2026-81718openssl_encrypt versions before 1.4.9 use under-parameterize…7.5
- CVE-2026-81719openssl_encrypt before 1.4.9 executes untrusted third-party …7.8
Are you affected by CVE-2026-81707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
