SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-81691

HIGH · CVSS 7.5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.9 are vulnerable due to inadequate validation of server URLs in the login and register_with_email functions, allowing the acceptance of unencrypted HTTP URLs and unconfigured hosts. This flaw enables attackers on the network path to intercept sensitive credentials such as client IDs, passwords, and JWTs, potentially leading to complete account takeover on keyserver systems. Organizations using affected versions should prioritize patching to mitigate the risk of credential theft and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81691
Severity
HIGH
CVSS
7.5
EPSS
0.20%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.

Related CVEs

Other vulnerabilities affecting the same vendor(s)