Shell Injection Vulnerability in OpenSSL_Encrypt Affecting Multiple Versions
CVE-2026-81698
9.3CRITICAL
What is CVE-2026-81698?
The OpenSSL_Encrypt tool is vulnerable to shell injection due to improper handling of metadata fields in its info command. This issue allows an attacker to inject and execute shell commands by manipulating the metadata values, especially in fields like pepper_name. Users are at risk if they copy the printed command-line interface (CLI) block into their shell, potentially leading to unauthorized command execution.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
