SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81703

MEDIUM · CVSS 5.5 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.9 are vulnerable due to inadequate validation of the encryption status for embedded post-quantum private keys in file metadata. This flaw allows attackers to create files containing unencrypted PQC keys that can be decrypted with any password, enabling them to bypass authentication and generate attacker-controlled plaintext while compromising data integrity. Organizations utilizing affected versions of OpenSSL, especially those handling sensitive cryptographic operations, should prioritize patching this vulnerability to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81703
Severity
MEDIUM
CVSS
5.5
EPSS
0.16%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification.

Related CVEs

Other vulnerabilities affecting the same vendor(s)