云虫漏洞情报

CVE-2026-81701 - openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys. - 漏洞详情

漏洞编号:CVE-2026-81701

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-81701

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-347

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.

相关链接

相关漏洞

« 返回首页