Junglewise Threat Intelligence

CVE-2026-54073: VeraCrypt plaintext markers in hidden volume creation

CVE-2026-54073 · Severity: info · CVSS 0 · Published 2026-08-21

Technologies: Veracrypt.

Executive brief

VeraCrypt is disk encryption software that protects data on laptops, external drives, and other storage devices. A bug in versions 1.26.6–1.26.28 left predictable, unencrypted markers on disk when creating hidden volumes, potentially making it easier for forensic investigators to detect the presence of hidden data during legal seizures. The actual encrypted data remains protected, but the plausible deniability of the hidden volume is weakened.

Technical details

A file-hosted hidden volume creation flaw bypassed the standard encrypted write path (EncryptDataUnits). Instead, the FormatNoFs and FormatFat functions directly wrote raw zeroed sectors at predictable 128 MiB intervals using WriteFile, creating deterministic plaintext markers in ciphertext regions. This only affected hidden volumes forced to quick format (non-hidden file containers were unaffected). The vulnerability required local access during volume creation; it does not disclose hidden volume content or break VeraCrypt's encryption. The fix, released in version 1.26.29, ensures hidden volume formatting uses only the encrypted write path, preserving forensic deniability.

Affected products

  • VeraCrypt VeraCrypt 1.26.6 through 1.26.28

Timeline

  • 2026-08-21: disclosed
  • 2026-06-12: patched: Fixed in version 1.26.29

References