Namespace Collision in OpenSSL Encrypt Affecting IdentityStore
CVE-2026-81706
9.3CRITICAL
What is CVE-2026-81706?
OpenSSL Encrypt versions prior to 1.4.9 are susceptible to namespace collisions within the IdentityStore. This flaw allows attackers to create shadowed contact entries that remain hidden until the legitimate user deletes their associated identity. Upon deletion, the shadowed contact becomes visible and links to the attacker's encryption keys. This facilitates silent key substitution for encrypted files, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
