CVE-2026-81707 - openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email

CVE Advisories
Post Reply
Starburst-David
Posts: 286
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-81707 - openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email

Post by Starburst-David »

CVE ID :CVE-2026-81707
Published : Aug. 27, 2026, 5:21 p.m. | 1 hour, 57 minutes ago
Description :openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.
Severity: 9.8 | CRITICAL

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-81707
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”