SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81682

MEDIUM · CVSS 6.2 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.9 are vulnerable due to insecure file permissions in the desktop GUI, which allows decrypted plaintext files to be created with world-readable defaults. This flaw enables unprivileged local users on multi-user systems to access sensitive decrypted output files, potentially leading to data exposure. Organizations using affected versions of OpenSSL, particularly those operating in multi-user environments, should prioritize patching to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81682
Severity
MEDIUM
CVSS
6.2
EPSS
0.12%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.