MEDIUMVulnerability

CVE-2026-81706

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.

Properties

severity
MEDIUM
score
6.8
epss_score
0.00132
cve_id
CVE-2026-81706
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
published_at
2026-08-27T17:21:01.293
last_modified
2026-09-01T17:57:53.053
epss_percentile
0.03052

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Insufficient Verification of Data Authenticity

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81706 — Ninja Signal Threat Intelligence | Ninja Signal