PT-2026-76607 · Unknown · Openssl-Encrypt
CVE-2026-74871
·
Published
2026-08-17
·
Updated
2026-08-17
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.6
Description
A key derivation flaw exists in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single Key Derivation Function (KDF) and no prior hashing stage, attackers can bypass memory-hard key derivation. This allows for offline password cracking at SHA-256 speed, ignoring the configured KDF cost.
Recommendations
Update openssl encrypt to version 1.4.6 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt