SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81680

MEDIUM · CVSS 4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.9 are vulnerable to an authentication bypass in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. This flaw enables unauthorized modification of file headers, potentially compromising data recovery mechanisms intentionally established by the file owner. Organizations utilizing affected versions of OpenSSL should prioritize updating to mitigate the risk of data loss and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81680
Severity
MEDIUM
CVSS
4
EPSS
0.14%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.

Related CVEs

Other vulnerabilities affecting the same vendor(s)