CVE-2026-81717
CVE-2026-81717 is a low-severity vulnerability in Jahlives Openssl Encrypt with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-347.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- CVSS v4: 9.3
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-347
- Affected product: Jahlives Openssl Encrypt
- Published:
- Last modified:
Description
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive — including a root-level autorun payload — are not detected and integrity verification still passes. Additionally, a globally constant, source-embedded KDF salt (_LEGACY_FIXED_SALT) is used to derive the drive encryption key for any drive lacking a per-drive salt file, defeating precomputation resistance and enabling an offline rainbow-table attack.
Frequently asked questions
- What is CVE-2026-81717?
- openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive — including a root-level autorun payload — are not detected and integrity verification still passes. Additionally, a globally constant, source-embedded KDF salt (_LEGACY_FIXED_SALT) is used to derive the drive encryption key for any drive lacking a per-drive salt file, defeating precomputation resistance and enabling an offline rainbow-table attack.
- How severe is CVE-2026-81717?
- CVE-2026-81717 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over physical access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-81717 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-81717?
- CVE-2026-81717 affects Jahlives Openssl Encrypt. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-81717?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-81717 published?
- CVE-2026-81717 was published on 2026-08-27 and last updated on 2026-09-02.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-8jx3-27qf-3p97
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-integrity-bypass-via-added-files
Affected products (1)
- cpe:2.3:a:jahlives:openssl_encrypt:*:*:*:*:*:python:*:*
More vulnerabilities in Jahlives Openssl Encrypt
- CVE-2026-81702 — Critical (CVSS 9.8): openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json,…
- CVE-2026-81701 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in…
- CVE-2026-81700 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that…
- CVE-2026-74901 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption…
- CVE-2026-74900 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures…
- CVE-2026-74899 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes…
All CVEs affecting Jahlives Openssl Encrypt →
Other CWE-347 (Improper Verification of Cryptographic Signature) vulnerabilities
- CVE-2026-5430 — Critical (CVSS 10.0): The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or…
- CVE-2026-56451 — Critical (CVSS 10.0): A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly…
- CVE-2026-48558 — Critical (CVSS 10.0): SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the…
- CVE-2023-25574 — Critical (CVSS 10.0): `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI).…
- CVE-2024-45409 — Critical (CVSS 10.0): The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <=…
- CVE-2024-32962 — Critical (CVSS 10.0): xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default…
Browse all CWE-347 (Improper Verification of Cryptographic Signature) vulnerabilities →