Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-81702

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 3.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-81702


Contact Us

Shodan ® - All rights reserved