CMS_decrypt/PKCS7_decrypt of the component Decryption API. Executing a manipulation can lead to covert channel.This vulnerability appears as CVE-2026-42768. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.