CVE-2026-81682: Jahlives OpenSSL Encrypt

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.

Affected products

  • Jahlives OpenSSL Encrypt: before 1.4.9 (fixed in 1.4.9)

Published 2026-08-27. Last modified 2026-09-23.