CyberRota Analysis
AI-GeneratedEnte's 2of3 card format version 1 prior to the 2026.07.28 update is vulnerable due to the storage of secret byte lengths and 32-bit FNV-1a checksums in cleartext, enabling attackers to perform offline brute-force attacks on low-entropy or predictable secrets. Organizations using this version should prioritize updating to the latest release to mitigate the risk of unauthorized access to sensitive information. This vulnerability is particularly relevant for entities relying on Ente's cloud services and security tools for data protection.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one card to test candidate secrets offline and recover low-entropy or predictable secrets. This issue is fixed in version 2026.07.28.