PT-2026-76624 · Pecl · Openssl-Encrypt
CVE-2026-74888
·
Published
2026-08-17
·
Updated
2026-08-17
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
The software uses a non-standard PBKDF2 (Password-Based Key Derivation Function 2) key derivation construction. This implementation performs one iteration per call within an outer loop, resulting in a Key Derivation Function (KDF) with security properties that have not been formally analyzed. This weakness allows attackers to crack passwords protecting legacy encrypted files more efficiently than they could with standard PBKDF2 implementations.
Recommendations
Update openssl encrypt to version 1.4.0 or later.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt