CVE-2026-95105
Last modified
CVE-2026-95105 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| danielberkompas | cloak | >= 0.1.0-pre, < * |
| danielberkompas | cloak | >= 2bd17019e285b55c5c218cc842537bf9280f24c3, < * |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-95105?
How severe is CVE-2026-95105?
How do I fix CVE-2026-95105?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9506This vulnerability exists in Bagisto due to improper validat…8.7
- CVE-2026-9507A session fixation vulnerability has been identified in osTi…5.1
- CVE-2026-9508Incorrect permission settings on a critical resource in Supr…10
- CVE-2026-9509An unhandled exception in Suprema BioStar 2 (Server), versio…8.7
- CVE-2026-95102WebSocket endpoints lack proper authentication mechanisms, e…9.4
- CVE-2026-95104Stack-based buffer overflow vulnerability exists in BUFFALO …7.5
- CVE-2026-95106Gitea accepted pushed Git trees containing two entries with …9.1
- CVE-2026-9511A vulnerability was identified in Totolink CA750-PoE 6.2c.51…6.3
- CVE-2026-95112When processing issue and comment bodies, Gitea scanned the …6.5
- CVE-2026-9512A security flaw has been discovered in Totolink CA750-PoE 6.…6.3
- CVE-2026-95125libming through 0.4.8 contains a heap buffer overflow in r_r…
- CVE-2026-9513A weakness has been identified in Totolink CA750-PoE 6.2c.51…6.3
Are you affected by CVE-2026-95105?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
