What is CVE-2026-74873?
CVE-2026-74873 affects openssl_encrypt versions prior to 1.4.0, where passwords passed via the --password CLI argument are exposed in process listings. This allows any system user to retrieve plaintext passwords by reading process arguments through commands like ps aux or /proc/[pid]/cmdline. Upgrading to version 1.4.0 or later mitigates the issue.
Azərbaycanca: CVE-2026-74873 openssl_encrypt alətinin 1.4.0-dan əvvəlki versiyalarında aşkarlanıb. --password CLI arqumenti ilə ötürülən parollar process listing-lərdə açıq şəkildə görünür, bu da istənilən sistem istifadəçisinə həssas məlumatları oxumağa imkan verir. Bu boşluqdan qorunmaq üçün openssl_encrypt-i 1.4.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What versions of openssl_encrypt are affected by CVE-2026-74873?
CVE-2026-74873 affects openssl_encrypt versions prior to 1.4.0.
How can I mitigate the vulnerability described in CVE-2026-74873?
Upgrading openssl_encrypt to version 1.4.0 or later mitigates this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.