CVE-2026-81682

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 17:20

Updated : 2026-08-31 16:19


NVD link : CVE-2026-81682

Mitre link : CVE-2026-81682

CVE.ORG link : CVE-2026-81682


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions