Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification. | |
| Title | openssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC Key | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T18:21:11.706Z
Reserved: 2026-08-27T11:12:29.817Z
Link: CVE-2026-81703
No data.
Status : Received
Published: 2026-08-27T17:21:00.833
Modified: 2026-08-27T17:21:00.833
Link: CVE-2026-81703
No data.
OpenCVE Enrichment
No data.