Plugin Signing Trust Anchor Enrollment Bypass in OpenSSL Encrypt by Jahlives
CVE-2026-81714
9.3CRITICAL
What is CVE-2026-81714?
The OpenSSL Encrypt plugin versions up to 1.4.8 are vulnerable to a bypass in the plugin signing trust anchor enrollment process. This vulnerability enables an attacker to enroll their colliding key as a trusted anchor by taking advantage of the suffix-tolerant fingerprint matching mechanism in place, which can mislead an operator into confirming a short and easily forgeable GPG key ID. Consequently, this could allow malicious plugins to be endorsed under the ENFORCE signature policy, posing a significant security risk. The issue is resolved in version 1.4.9, which mandates that the confirmed key must match the full primary-key fingerprint.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
