Description
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping.

Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error.

This issue affects cloak: from 0.1.0-pre onward.
Published: 2026-10-06
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Data integrity compromise via forged plaintexts
Action: Apply Workaround
AI Analysis

Impact

The flaw lies in Cloak’s AES-CTR cipher where ciphertext is stored without any form of integrity protection. Decrypt/2 validates only the key tag and length, allowing an attacker who can modify encrypted data to flip bits in the ciphertext. Because CTR mode is a stream cipher, any bit changes in the ciphertext produce the same bit changes in the decrypted plaintext, enabling the attacker to produce arbitrary chosen plaintext values. This effectively permits data tampering and could be used to forge tokens, credentials, or any encrypted data stored by the application.

Affected Systems

The vulnerability affects all releases of the Cloak library from version 0.1.0-pre onward for the vendor danielberkompas Cloak.

Risk and Exploitability

With a CVSS score of 8.2 the vulnerability is considered high severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack requires write access to the encrypted store, which can be obtained via SQL‑injection, a compromised database replica, or direct file manipulation. Once write access is achieved, the attacker can modify any ciphertext of the same length as the targeted plaintext, causing the application to decrypt it to a value of the attacker’s choosing. The impact spans confidentiality and integrity for data encrypted with the vulnerable cipher and can undermine authentication or authorization mechanisms that rely on those encrypted values.

Generated by OpenCVE AI on October 6, 2026 at 11:45 UTC.

Remediation

Vendor Workaround

Configure the vault with Cloak.Ciphers.AES.GCM as the default cipher and re-encrypt existing values, for example with the cloak.migrate.ecto task from cloak_ecto. Then remove Cloak.Ciphers.AES.CTR and Cloak.Ciphers.Deprecated.AES.CTR from the vault configuration, so that ciphertext in the CTR format is no longer decrypted. AES-GCM authenticates the ciphertext and rejects modified values.


OpenCVE Recommended Actions

  • Configure the vault to use Cloak.Ciphers.AES.GCM as the default cipher and re‑encrypt existing values, for example by running the cloak.migrate.ecto task provided by cloak_ecto
  • Remove the deprecated AES.CTR and AES.CTR classes from the vault configuration so that ciphertext in the CTR format is no longer automatically decrypted
  • Limit write access to the encrypted store by tightening database permissions and preventing SQL injection or other means to modify the ciphertext

Generated by OpenCVE AI on October 6, 2026 at 11:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward.
Title Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping
First Time appeared Danielberkompas
Danielberkompas cloak
Weaknesses CWE-649
CPEs cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*
Vendors & Products Danielberkompas
Danielberkompas cloak
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Danielberkompas Cloak
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-10-06T11:40:42.775Z

Reserved: 2026-09-25T07:00:01.880Z

Link: CVE-2026-95105

cve-icon Vulnrichment

Updated: 2026-10-06T11:40:24.528Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:57.200

Modified: 2026-10-06T12:16:51.110

Link: CVE-2026-95105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T12:00:15Z

Weaknesses
  • CWE-649

    Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking