Integrity Bypass Vulnerability in openssl_encrypt by OpenSSL
CVE-2026-81717
9.3CRITICAL
What is CVE-2026-81717?
The openssl_encrypt package prior to version 1.4.9 contains significant vulnerabilities related to its portable USB drive functionality. This vulnerability allows an attacker with physical write access to a removable drive to potentially introduce unauthorized files, including a root-level autorun payload, which the integrity verification fails to detect. Furthermore, the use of a static, source-embedded KDF salt for key derivation on certain drives significantly weakens the encryption, making it susceptible to offline attacks such as rainbow table attacks.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
