PT-2026-76622 · Unknown · Openssl-Encrypt
CVE-2026-74886
·
Published
2026-08-17
·
Updated
2026-08-17
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
A plugin sandbox bypass exists because the
PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS MODULES set. AST (Abstract Syntax Tree) is a tree representation of the abstract syntactic structure of source code. Attackers can use string obfuscation or encoding to bypass AST analysis and import dangerous modules such as sys, shutil, multiprocessing, importlib, and pickle, leading to arbitrary code execution.Recommendations
Update openssl encrypt to version 1.4.0 or later.
Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt