Namespace Collision in OpenSSL Encrypt Affecting IdentityStore
CVE-2026-81706

9.3CRITICAL

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81706?

OpenSSL Encrypt versions prior to 1.4.9 are susceptible to namespace collisions within the IdentityStore. This flaw allows attackers to create shadowed contact entries that remain hidden until the legitimate user deletes their associated identity. Upon deletion, the shadowed contact becomes visible and links to the attacker's encryption keys. This facilitates silent key substitution for encrypted files, posing a significant risk to data integrity and confidentiality.

Affected Version(s)

openssl_encrypt 0 < 1.4.9

openssl_encrypt 1.4.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.