CVE-2026-81714: openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass

Published Aug 27, 2026
·
Updated

opensslencrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enrolltrustkey when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enroll an attacker's colliding key as a trusted anchor, which then vouches for malicious plugins under the ENFORCE signature policy. Version 1.4.9 fixes this by requiring the confirmed value to exactly match the full primary-key fingerprint (case-insensitive, whitespace-stripped).

Affected Software

1 affected component
openssl_encrypt openssl_encrypt<1.4.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openssl_encrypt (pip: openssl-encrypt) to a version that resolves this vulnerability.

    Fixed in 1.4.9
  2. Upgrade

    Upgrade openssl_encrypt (pip: openssl-encrypt) to a version that resolves this vulnerability.

    Patch openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass

Event History

Aug 27, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using openssl_encrypt version 1.4.8 or earlier are exposed when an operator enrolls a plugin-signing trust anchor and confirms a short GPG key ID. The impact applies where the ENFORCE signature policy relies on that enrolled anchor to validate plugins.

2

What does an attacker need to exploit it?

An attacker needs a GPG key whose short, approximately 32-bit key ID collides with the key ID presented for confirmation. They must cause an operator to confirm that short identifier during trust-anchor enrollment, allowing the colliding attacker key to be trusted.

3

Are installations safe if operators verify full fingerprints?

The vulnerable enrollment behavior accepts suffix matches, so safety depends on what value is confirmed during enrollment. Version 1.4.9 requires an exact match against the full primary-key fingerprint after case and whitespace normalization.

4

What can be done before upgrading?

Do not enroll plugin-signing trust anchors based on short GPG key IDs. Verify the complete primary-key fingerprint through a trusted channel before accepting a key, and avoid trusting newly enrolled anchors until that verification is complete.

5

How can I determine whether remediation is needed?

Check whether the installed openssl_encrypt version is 1.4.8 or earlier and review plugin-signing trust-anchor enrollments. Anchors enrolled after confirmation of a short key ID should be treated as needing revalidation against the full primary-key fingerprint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203