HIGHVulnerability

CVE-2026-81704

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.

Properties

severity
HIGH
score
7.5
epss_score
0.00198
cve_id
CVE-2026-81704
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-27T17:21:00.993
last_modified
2026-09-03T15:09:32.657
epss_percentile
0.09659

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Use of Password Hash With Insufficient Computational Effort

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81704 — Ninja Signal Threat Intelligence | Ninja Signal