Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jahlives
Jahlives openssl Encrypt |
|
| Vendors & Products |
Jahlives
Jahlives openssl Encrypt |
|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification. | |
| Title | openssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC Key | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T18:21:11.706Z
Reserved: 2026-08-27T11:12:29.817Z
Link: CVE-2026-81703
Updated: 2026-08-27T18:21:06.699Z
Status : Received
Published: 2026-08-27T17:21:00.833
Modified: 2026-08-27T20:18:53.680
Link: CVE-2026-81703
No data.
OpenCVE Enrichment
Updated: 2026-08-27T18:45:04Z
-
CWE-287
Improper Authentication