PT-2026-76618 · Unknown · Openssl-Encrypt
CVE-2026-74882
·
Published
2026-08-17
·
Updated
2026-08-17
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
An insecure default configuration exists where the
trusted proxies setting in IntegrityProxyConfig trusts the entire RFC 1918 private address space. This allows attackers located on private networks to forge client certificate headers, potentially bypassing mTLS (mutual Transport Layer Security) authentication if ProxyAuth validation is relaxed or modified.Recommendations
Update openssl encrypt to version 1.4.0 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt