CVE-2026-81701: openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin

Published Aug 27, 2026
·
Updated

opensslencrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.

Affected Software

1 affected component
OpenSSL OpenSSL<1.4.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openssl_encrypt to a version that resolves this vulnerability.

    Fixed in 1.4.9
  2. Compensating control

    Prevent loading unsigned plugins from the top-level plugins/ directory and from unknown subdirectories so that signature verification cannot be bypassed by directory placement.

Event History

Aug 27, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Installations running openssl_encrypt before 1.4.9 are exposed if an attacker can place an unsigned plugin in a top-level plugins/ directory or an unknown subdirectory that follows documented plugin installation paths.

2

What does an attacker need to exploit it?

The attacker needs the ability to place a malicious unsigned plugin in an affected plugin location. No authentication or user interaction is indicated by the supplied severity vector.

3

What is the impact if exploitation succeeds?

A malicious plugin can achieve arbitrary code execution in the CLI process. That process may have access to passwords and cryptographic keys, and the reported impact includes high confidentiality, integrity, and availability consequences.

4

How can I determine whether my deployment is affected?

Check whether the installed openssl_encrypt version is earlier than 1.4.9, then inspect top-level plugins/ directories and unknown plugin subdirectories for unsigned plugins installed through documented plugin paths.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203