CVE-2026-81704: openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus

Published Aug 27, 2026
·
Updated

opensslencrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.

Affected Software

1 affected component
OpenSSL OpenSSL<1.4.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openssl_encrypt (D-Bus CryptoService.EncryptFile handler) to a version that resolves this vulnerability.

    Fixed in 1.4.9

Event History

Aug 27, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using openssl_encrypt before 1.4.9 are exposed when encrypted files are produced through the D-Bus CryptoService.EncryptFile handler. The impact concerns the password-derived protection of those encrypted files.

2

What does an attacker need to exploit the weakness?

An attacker needs access to an encrypted file protected by the affected handler in order to conduct offline password guessing. No authentication or user interaction is required for the offline guessing attack.

3

Does exploitation require access to the running D-Bus service?

No. The described attack is offline password guessing against encrypted files, so the attacker can work from a copy of an affected encrypted file rather than interacting with the D-Bus service during guessing.

4

How can teams determine whether encrypted files may be affected?

Identify files encrypted by the CryptoService.EncryptFile handler in openssl_encrypt versions earlier than 1.4.9. Those files may have been protected using unstretched SHA-256 rather than Argon2id.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203