CRITICAL🇵🇱 Wersja polska

CVE-2026-74886

CVSS 9.3v4.0pub. 2026-08-17upd. 2026-09-01

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Jahlives OpenSSL Encrypt

    APP
    Jahlives
    < 1.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-81685CRITICAL9.3same product

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing att...

CVE-2026-81694CRITICAL9.3same product

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (o...

CVE-2026-81680CRITICAL9.3same product

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted...

CVE-2026-81681CRITICAL9.3same product

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encr...

CVE-2026-81695CRITICAL9.3same product

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr durin...