CVE-2026-81706
Received Received - Intake

OpenSSL Encrypt Identity Collision in IdentityStore

Vulnerability report for CVE-2026-81706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VulnCheck

Description

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl_encrypt to 1.4.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability CVE-2026-81706 affects openssl_encrypt versions before 1.4.9. It allows attackers to create hidden contact entries that replace legitimate keys when an own identity is deleted. This enables silent key substitution, letting attackers decrypt files encrypted to the original keys.

Impact Analysis

An attacker could silently replace your encryption keys, allowing them to decrypt files meant for you. This could lead to unauthorized access to sensitive data, especially if you delete and recreate identities or rotate keys.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and encryption, such as GDPR's encryption standards or HIPAA's safeguards for protected health information. Unauthorized decryption risks data breaches and non-compliance penalties.

Mitigation Strategies

Upgrade openssl_encrypt to version 1.4.9 or later to address the vulnerability. Verify any names appearing as both an own identity and a contact before deleting identities to prevent shadowed contact entries from becoming visible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart