CVE-2026-81685
LOW3.3CVSS v3
—CVSS v2
0.18%
EPSS (exploit probability)
CWE-116CWE
Description
openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot identifiers containing bidi overrides or line-separator characters to forge warning text and deceive users during file removal operations.
CVSS v3 vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.