Arbitrary Code Execution in openssl_encrypt by Unsigned Plugins
CVE-2026-81701
9.3CRITICAL
What is CVE-2026-81701?
The openssl_encrypt product versions prior to 1.4.9 have a significant vulnerability that permits unsigned plugins to bypass signature verification. This lack of stringent checks enables attackers to introduce malicious unsigned plugins into the top-level plugins directory or into unknown subdirectories. Once executed, these plugins can lead to arbitrary code execution in the command-line interface (CLI) process, allowing unauthorized access to sensitive information such as passwords and cryptographic keys. It is crucial for users to upgrade to newer versions to eliminate this risk.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
