Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-81680

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 4.9%
CVSS Severity
CVSS v3 Score 4.0
Products affected by CVE-2026-81680


Contact Us

Shodan ® - All rights reserved