Plugin Signing Trust Anchor Enrollment Bypass in OpenSSL Encrypt by Jahlives
CVE-2026-81714

9.3CRITICAL

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81714?

The OpenSSL Encrypt plugin versions up to 1.4.8 are vulnerable to a bypass in the plugin signing trust anchor enrollment process. This vulnerability enables an attacker to enroll their colliding key as a trusted anchor by taking advantage of the suffix-tolerant fingerprint matching mechanism in place, which can mislead an operator into confirming a short and easily forgeable GPG key ID. Consequently, this could allow malicious plugins to be endorsed under the ENFORCE signature policy, posing a significant security risk. The issue is resolved in version 1.4.9, which mandates that the confirmed key must match the full primary-key fingerprint.

Affected Version(s)

openssl_encrypt 0 < 1.4.9

openssl_encrypt 1.4.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.