CVE-2026-81704 HIGH

CVE-2026-81704: openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus

Vendor Jahlives
Product openssl_encrypt
Weakness CWE-916
Published August 27, 2026
Last update August 28, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated