PT-2026-76609 · Unknown · Openssl-Encrypt

CVE-2026-74873

·

Published

2026-03-31

·

Updated

2026-08-17

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description Passwords provided through the --password CLI argument are exposed in process listings, which are accessible to all system users. This allows attackers to retrieve plaintext passwords and keystore passwords by reading process arguments via ps aux or /proc/[pid]/cmdline.
Recommendations Update openssl encrypt to version 1.4.0 or later. Avoid using the --password CLI argument to pass sensitive information.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74873
GHSA-H3M5-P59H-X88P
PYSEC-2026-3753

Affected Products

Openssl-Encrypt