Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jahlives
Jahlives openssl Encrypt |
|
| Vendors & Products |
Jahlives
Jahlives openssl Encrypt |
|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps only its path in SharedPreferences, and migrates/scrubs existing cleartext values. | |
| Title | openssl_encrypt before 1.4.9 Plaintext Private Key Storage | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T18:19:35.348Z
Reserved: 2026-08-27T11:11:30.934Z
Link: CVE-2026-81683
Updated: 2026-08-27T18:19:30.360Z
Status : Received
Published: 2026-08-27T17:20:57.810
Modified: 2026-08-27T20:18:52.200
Link: CVE-2026-81683
No data.
OpenCVE Enrichment
Updated: 2026-08-27T18:45:04Z
-
CWE-312
Cleartext Storage of Sensitive Information