Disk Encryption Vulnerability in VeraCrypt
CVE-2026-54073

4.6MEDIUM

Key Information:

Vendor

Veracrypt

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-54073?

A flaw in VeraCrypt's handling of file-hosted hidden volumes allows for the creation of identifiable plaintext markers in encrypted volumes due to improper formatting functions. These markers, present at predictable intervals, can undermine plausible deniability during forensic examinations, although they do not reveal the content of hidden volumes nor compromise the encryption strength. Users are advised to upgrade to the fixed version 1.26.29 to mitigate this issue.

Affected Version(s)

VeraCrypt >= 1.26.6, < 1.26.29

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.