SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81685

LOW · CVSS 3.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.9 are vulnerable due to inadequate sanitization of recovery-slot metadata in the desktop GUI, which allows for the injection of control characters and line separators. This can lead to user deception during irreversible file removal operations, as attackers can manipulate warning messages displayed to users. Organizations using affected versions should prioritize updating to mitigate potential exploitation risks, particularly those with sensitive data handling processes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81685
Severity
LOW
CVSS
3.3
EPSS
0.18%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot identifiers containing bidi overrides or line-separator characters to forge warning text and deceive users during file removal operations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)