CVE-2026-81688: Insecure Plaintext Hash Metadatacve-2026-81688-insecure-plaintext-hash-metadata
Storing an unkeyed plaintext hash (such as 'original_hash' or 'plaintext_hash') in metadata headers allows offline plaintext confirmation and cross-file correlation without the decryption key.