Impact
VeraCrypt’s hidden volume creation function used quick format from version 1.26.6 to 1.26.29, writing raw zeroed sectors at 128 MiB intervals. These writes bypass the normal encrypted data unit path and leave deterministic plaintext markers where random ciphertext should exist. While the markers do not expose hidden‑volume contents or degrade encryption strength, they undermine plausible deniability by giving forensic analysts identifiable patterns to detect hidden volumes.
Affected Systems
The affected product is VeraCrypt. Versions from 1.26.6 through 1.26.28 contain the issue; the problem is corrected in release 1.26.29 and later.
Risk and Exploitability
The vulnerability has a CVSS score of 4.6, indicating moderate severity. No EPSS score is available and the issue is not listed in CISA KEV. The attack vector is inferred from the description because the hidden volume creation requires local user interaction on a file‑hosted container. An attacker cannot obtain confidential data or execute code; the risk is limited to forensic visibility and loss of plausible deniability under investigative circumstances.
OpenCVE Enrichment