CVE-2026-81718: openssl_encrypt before 1.4.9 Weak Cryptographic Parameters

Published Aug 27, 2026
·
Updated

opensslencrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or encrypted files can brute-force wrapping passwords offline using GPU or ASIC acceleration.

Affected Software

1 affected component
OpenSSL OpenSSL<1.4.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openssl_encrypt to a version that resolves this vulnerability.

    Fixed in 1.4.9

Event History

Aug 27, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to password-cracking attacks?

Organizations or users whose PQC keyfiles or encrypted files were created with affected versions and could be obtained by an attacker are exposed. The attack is offline, so an attacker does not need access to a running service after acquiring the protected files.

2

What does an attacker need to exploit this issue?

An attacker needs a copy of an affected keyfile or encrypted file and can then attempt to brute-force its wrapping password offline using GPU or ASIC acceleration. No privileges or user interaction are required according to the supplied severity vector.

3

Are files created before upgrading still at risk?

The data identifies weak PBKDF2-HMAC-SHA256 iteration counts in versions before 1.4.9, but does not state that upgrading changes protection for files already created. Treat previously generated keyfiles and encrypted files as potentially susceptible if an attacker may have obtained them.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203