CRITICALVulnerability

CVE-2026-81702

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

Properties

severity
CRITICAL
score
9.8
epss_score
0.00139
cve_id
CVE-2026-81702
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-27T17:21:00.680
last_modified
2026-09-03T15:09:14.280
epss_percentile
0.0358

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Insufficient Verification of Data Authenticity

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81702 — Ninja Signal Threat Intelligence | Ninja Signal