openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.
References
| Link | Resource |
|---|---|
| https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-wxx9-p55f-wm34 | Vendor Advisory |
| https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-arbitrary-code-execution-via-unsigned-plugin | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-27 17:21
Updated : 2026-09-01 18:12
NVD link : CVE-2026-81701
Mitre link : CVE-2026-81701
CVE.ORG link : CVE-2026-81701
JSON object : View
Products Affected
jahlives
- openssl_encrypt
CWE
CWE-347
Improper Verification of Cryptographic Signature
