PT-2026-76607 · Unknown · Openssl-Encrypt

CVE-2026-74871

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.6
Description A key derivation flaw exists in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single Key Derivation Function (KDF) and no prior hashing stage, attackers can bypass memory-hard key derivation. This allows for offline password cracking at SHA-256 speed, ignoring the configured KDF cost.
Recommendations Update openssl encrypt to version 1.4.6 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74871
GHSA-VXF9-VWP6-2W43
PYSEC-2026-3976

Affected Products

Openssl-Encrypt