PT-2026-76624 · Pecl · Openssl-Encrypt

CVE-2026-74888

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description The software uses a non-standard PBKDF2 (Password-Based Key Derivation Function 2) key derivation construction. This implementation performs one iteration per call within an outer loop, resulting in a Key Derivation Function (KDF) with security properties that have not been formally analyzed. This weakness allows attackers to crack passwords protecting legacy encrypted files more efficiently than they could with standard PBKDF2 implementations.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74888
GHSA-743F-89FG-X288
PYSEC-2026-3764

Affected Products

Openssl-Encrypt