CVE-2026-81696
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-117
- Published
- 2026-08-27
- Last modified
- 2026-08-27
Affected products
- jahlives openssl_encrypt
- jahlives openssl_encrypt
Weakness type
Related vulnerabilities
- CVE-2026-14350 — Vulnerabilities exists in IBM Cloud Pak for Data System
- CVE-2026-9736 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-15603 — morgan vulnerable to Log Forging via unescaped Unicode line separators
- CVE-2026-81695 — openssl_encrypt before 1.4.9 Terminal Injection via key_id
- CVE-2026-81694 — verify-usb before 1.4.9 Output Injection via Unsanitized Filenames
- CVE-2026-54511 — @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
- CVE-2026-44256 — Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username
- CVE-2026-74885 — openssl_encrypt before 1.4.0 Logging Bug and Race Condition