Description
Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one card to test candidate secrets offline and recover low-entropy or predictable secrets. This issue is fixed in version 2026.07.28.
Published: 2026-08-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ente’s 2of3 card format version 1 stored the secret byte length and a 32‑bit FNV‑1a checksum in cleartext on every card. An adversary possessing a single leaked card can use this information to test candidate secrets offline and recover secrets that are low‑entropy or predictable.

Affected Systems

All deployments of Ente 2of3 card format v1 that predate the 2026.07.28 release are affected. The vulnerability exists in any configuration that writes the secret length and checksum to the card payload.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate risk, and the EPSS score of less than 1 % shows a very low probability of exploitation at present. The issue is not listed in CISA KEV. Attackers need only obtain a single card and can perform offline password guessing; based on the description, it is inferred that no network or privileged access is required. If an attacker recovers a low‑entropy secret, it is inferred that confidentiality of associated data is fully compromised.

Generated by OpenCVE AI on August 12, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Ente version 2026.07.28 or later, which removes the cleartext checksum and secret length from the card format.
  • If any secrets were stored using the vulnerable card format, rotate those keys or secrets to a new, high‑entropy value.
  • Verify that no systems continue to use Ente 2of3 card format v1 or earlier releases, and discontinue support for those versions if still in use.

Generated by OpenCVE AI on August 12, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Ente
Ente ente
Vendors & Products Ente
Ente ente

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one card to test candidate secrets offline and recover low-entropy or predictable secrets. This issue is fixed in version 2026.07.28.
Title Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T13:57:59.751Z

Reserved: 2026-08-11T14:41:20.122Z

Link: CVE-2026-73230

cve-icon Vulnrichment

Updated: 2026-08-13T13:57:56.012Z

cve-icon NVD

Status : Received

Published: 2026-08-11T20:18:48.257

Modified: 2026-08-13T15:20:10.707

Link: CVE-2026-73230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:34Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor