CRITICAL 9.3 NVD
CVE-2026-81702
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public ke
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-q8p3-7h6h-ghfr
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-key-substitution-via-ide
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-27 via NVD.
Risk Timeline
CVE Disclosed2026-08-27 · -1 days ago
Remediation Resources
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.