PT-2026-76618 · Unknown · Openssl-Encrypt

CVE-2026-74882

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description An insecure default configuration exists where the trusted proxies setting in IntegrityProxyConfig trusts the entire RFC 1918 private address space. This allows attackers located on private networks to forge client certificate headers, potentially bypassing mTLS (mutual Transport Layer Security) authentication if ProxyAuth validation is relaxed or modified.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74882
GHSA-2592-7M3G-7FQ6
PYSEC-2026-3744

Affected Products

Openssl-Encrypt