Impact
Ente’s 2of3 card format version 1 stored the secret byte length and a 32‑bit FNV‑1a checksum in cleartext on every card. An adversary possessing a single leaked card can use this information to test candidate secrets offline and recover secrets that are low‑entropy or predictable.
Affected Systems
All deployments of Ente 2of3 card format v1 that predate the 2026.07.28 release are affected. The vulnerability exists in any configuration that writes the secret length and checksum to the card payload.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk, and the EPSS score of less than 1 % shows a very low probability of exploitation at present. The issue is not listed in CISA KEV. Attackers need only obtain a single card and can perform offline password guessing; based on the description, it is inferred that no network or privileged access is required. If an attacker recovers a low‑entropy secret, it is inferred that confidentiality of associated data is fully compromised.
OpenCVE Enrichment