openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jahlives
Jahlives openssl Encrypt |
|
| Vendors & Products |
Jahlives
Jahlives openssl Encrypt |
|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files. | |
| Title | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-27T14:51:08.461Z
Updated: 2026-08-27T17:38:57.272Z
Reserved: 2026-08-27T11:12:29.818Z
Link: CVE-2026-81706
Updated: 2026-08-27T17:38:52.874Z
Status : Undergoing Analysis
Published: 2026-08-27T17:21:01.293
Modified: 2026-08-28T18:56:34.447
Link: CVE-2026-81706
No data.