Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-81683

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps only its path in SharedPreferences, and migrates/scrubs existing cleartext values.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 0.0%
CVSS Severity
CVSS v3 Score 8.4
Products affected by CVE-2026-81683


Contact Us

Shodan ® - All rights reserved