CVE-2026-73230: Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets
Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one card to test candidate secrets offline and recover low-entropy or predictable secrets. This issue is fixed in version 2026.07.28.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ente 2of3 cardsto a version that resolves this vulnerability.Fixed in 2026.07.28
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73230?
The severity of CVE-2026-73230 is rated as 33, indicating a moderate risk level.
How do I fix CVE-2026-73230?
To fix CVE-2026-73230, update to a patched version of Ente that addresses the exposed checksum issue.
What does CVE-2026-73230 exploit?
CVE-2026-73230 exploits the storage of secret byte length and checksum in cleartext, allowing offline guessing of low-entropy secrets.
Which version of Ente is affected by CVE-2026-73230?
CVE-2026-73230 affects the Ente 2of3 card format version 1 prior to the update on 2026.07.28.
What is the main consequence of CVE-2026-73230?
The main consequence of CVE-2026-73230 is the potential for attackers to recover low-entropy secrets through offline guessing.