What is CVE-2026-74870?
CVE-2026-74870 is an information exposure vulnerability in openssl_encrypt (pip) versions <= 1.4.7 where diagnostic commands 'hsm fido2-test' and 'hsm onlykey-test' unconditionally print the full derived hardware pepper as hex to stdout/stderr. Users are advised to update to the latest patched version immediately.
Azərbaycanca: CVE-2026-74870, openssl_encrypt (pip) kitabxanasının 1.4.7 və aşağı versiyalarında aşkarlanmış məlumat sızması zəifliyidir. 'hsm fido2-test' və 'hsm onlykey-test' diaqnostik əmrləri cihaza məxsus gizli açarı konsola açıq mətn şəklində çap edir. Bu zəiflikdən qorunmaq üçün dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of the openssl_encrypt library are affected by CVE-2026-74870?
CVE-2026-74870 affects openssl_encrypt (pip) versions 1.4.7 and below.
What sensitive data is exposed through the exploitation of CVE-2026-74870?
The vulnerability causes the diagnostic commands 'hsm fido2-test' and 'hsm onlykey-test' to unconditionally print the full derived hardware pepper as hex to the console.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.