CVE-2026-81683Jahlives · Openssl_encrypt
Vulnerability data via NVD (ingested)
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps only its path in SharedPreferences, and migrates/scrubs existing cleartext values.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-81683product:"Jahlives Openssl Encrypt"http.html:"Openssl Encrypt"More intel sources (5)
vuln:CVE-2026-81683vulnerabilities.cve_id: CVE-2026-81683CVE-2026-81683CVE-2026-81683"CVE-2026-81683" exploit -site:nvd.nist.gov