CVE-2026-81704CWE-916

CVE-2026-81704

High · published August 27, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
9.7
In the wild
Unconfirmed
What it is

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00198 · 9.7th percentile
Weakness
CWE-916 · Use of Password Hash With Insufficient Computational Effort
Published
2026-08-27T21:21Z
Affected products (1)
ProductVersionsFixed in
jahlives/openssl_encrypt< 1.4.91.4.9
References (2)
EPSS history
Timeline
  • 27 AUG 14:51Z
    openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
    cvelistv5