CRITICALVulnerability

CVE-2026-81701

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.

Properties

severity
CRITICAL
score
9.8
epss_score
0.00292
cve_id
CVE-2026-81701
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-27T17:21:00.533
last_modified
2026-09-01T18:12:15.613
epss_percentile
0.2149

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81701 — Ninja Signal Threat Intelligence | Ninja Signal