CRITICALVulnerability

CVE-2026-81707

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.

Properties

severity
CRITICAL
score
9.8
cve_id
CVE-2026-81707
signal_observed_at
2026-09-23T22:44:39+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-27T17:21:01.440
last_modified
2026-09-23T17:17:42.730

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81707 — Ninja Signal Threat Intelligence | Ninja Signal