Shell Injection Vulnerability in OpenSSL_Encrypt Affecting Multiple Versions
CVE-2026-81698

9.3CRITICAL

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81698?

The OpenSSL_Encrypt tool is vulnerable to shell injection due to improper handling of metadata fields in its info command. This issue allows an attacker to inject and execute shell commands by manipulating the metadata values, especially in fields like pepper_name. Users are at risk if they copy the printed command-line interface (CLI) block into their shell, potentially leading to unauthorized command execution.

Affected Version(s)

openssl_encrypt 0 < 1.4.9

openssl_encrypt 1.4.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.