Junglewise Threat Intelligence

CVE-2026-81706: openssl_encrypt namespace collision in IdentityStore allowing key substitution

CVE-2026-81706 · Severity: medium · CVSS 6.8 · Published 2026-08-27

Technologies: openssl-encrypt (PyPI), Jahlives Openssl Encrypt. Vendors: PyPI, Jahlives.

Executive brief

openssl_encrypt is a file encryption tool that manages identities and contacts for key-based encryption. A flaw in versions before 1.4.9 allows attackers to create hidden duplicate contact entries with the same name as a legitimate user identity. When the user later deletes their own identity (a routine operation after key rotation), the hidden contact surfaces and silently substitutes the attacker's encryption key, causing files encrypted to that trusted name to actually use the attacker's key without the user's knowledge.

Technical details

The vulnerability is a namespace collision (CWE-706) in the IdentityStore component where the add_identity function does not validate whether a name being imported as a contact already exists as an own identity. The get_by_name lookup checks own identities (base_path/<name>) before contacts (contacts/<name>), making shadowed contacts invisible while the own identity exists. The delete_identity function removed only the own identity without checking for shadowed contacts, leaving the attacker's contact in place. Upon deletion, get_by_name then resolves to the attacker's keys, enabling silent key substitution for encryption operations. The vulnerability requires that an attacker first gets their contact bundle imported under a chosen name, then waits for the user to delete their own identity. The fix in 1.4.9 prevents the collision by refusing to store a name that exists as the other kind, removes both locations on deletion, and surfaces collisions in the identity list output.

Affected products

  • jahlives openssl_encrypt before 1.4.9

Timeline

  • 2026-08-27: disclosed
  • 2026-08-12: patched: Version 1.4.9 released

References

Related threats