Authentication Bypass in OpenSSL Encrypt Affects Multiple Versions
CVE-2026-81703
8.7HIGH
What is CVE-2026-81703?
The OpenSSL Encrypt vulnerability exposes a critical flaw in versions prior to 1.4.9, where the encryption status of embedded post-quantum private keys is not validated. Malicious actors can exploit this issue by crafting files with unencrypted embedded PQC keys, allowing decryption under any password. This process not only circumvents authentication mechanisms but also enables the generation of attacker-crafted plaintext, leading to potential data exposure and integrity verification failures.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
