PT-2026-76622 · Unknown · Openssl-Encrypt

CVE-2026-74886

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description A plugin sandbox bypass exists because the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS MODULES set. AST (Abstract Syntax Tree) is a tree representation of the abstract syntactic structure of source code. Attackers can use string obfuscation or encoding to bypass AST analysis and import dangerous modules such as sys, shutil, multiprocessing, importlib, and pickle, leading to arbitrary code execution.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74886
GHSA-9PGJ-V69P-Q586
PYSEC-2026-3763

Affected Products

Openssl-Encrypt