CVE-2026-81683 - openssl_encrypt before 1.4.9 Plaintext Private Key Storage

CVE Advisories
Post Reply
Starburst-David
Posts: 286
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-81683 - openssl_encrypt before 1.4.9 Plaintext Private Key Storage

Post by Starburst-David »

CVE ID :CVE-2026-81683
Published : Aug. 27, 2026, 5:20 p.m. | 1 hour, 57 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps only its path in SharedPreferences, and migrates/scrubs existing cleartext values.
Severity: 8.4 | HIGH

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-81683
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”