CVE-2026-81700 CRITICAL

CVE-2026-81700: openssl_encrypt before 1.4.9 GPG Signature Verification Bypass

Vendor Jahlives
Product openssl_encrypt
Weakness CWE-347
Published August 27, 2026
Last update August 27, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host process.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

04Related CVE