CVE-2026-81686
openssl_encrypt before 1.4.9 D-Bus Properties Authorization Bypass
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th
openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call Set without authorization and set MaxConcurrentOperations (to 0/negative, causing the concurrency gate to refuse all subsequent operations, or to a huge value removing the limit) or the unbounded DefaultTimeout, resulting in a persistent denial of service of the root daemon. The D-Bus service exists only on the 1.4.x line and was removed in 1.5.x.
| CWE | CWE-20 |
| Vendor | jahlives |
| Product | openssl_encrypt |
| Published | Aug 27, 2026 |
| Last Updated | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for jahlives openssl_encrypt
Be the first to know when new medium vulnerabilities affecting jahlives openssl_encrypt are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
jahlives / openssl_encrypt
0 < 1.4.9