PT-2026-76630 · Unknown · Openssl-Encrypt

CVE-2026-74894

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description An authentication bypass exists in the verify api token() function, which accepts any non-empty Bearer token string without proper validation. This allows attackers to provide any Bearer token in the Authorization header to upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user.
Recommendations Update to version 1.4.0 or later. As a temporary workaround, restrict access to the verify api token() function to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74894
GHSA-4G2C-WPGJ-49W8
PYSEC-2026-3769

Affected Products

Openssl-Encrypt