PT-2026-76609 · Unknown · Openssl-Encrypt
CVE-2026-74873
·
Published
2026-03-31
·
Updated
2026-08-17
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
Passwords provided through the
--password CLI argument are exposed in process listings, which are accessible to all system users. This allows attackers to retrieve plaintext passwords and keystore passwords by reading process arguments via ps aux or /proc/[pid]/cmdline.Recommendations
Update openssl encrypt to version 1.4.0 or later.
Avoid using the
--password CLI argument to pass sensitive information.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl-Encrypt