What is CVE-2026-74877?
A missing ownership verification vulnerability in the `revoke_key` method of the `openssl_encrypt` library, affecting versions before 1.4.0, allows authenticated clients to revoke any other client's key. Attackers can bypass intended restrictions by providing a valid ML-DSA signature, enabling unauthorized key revocation. Users are advised to upgrade to version 1.4.0 or later.
Azərbaycanca: openssl_encrypt kitabxanasının 1.4.0-dan əvvəlki versiyalarında `revoke_key` metodunda aşkarlanan mülkiyyət yoxlanışı zəifliyi autentifikasiya olunmuş müştərilərə istənilən digər müştərinin açarını ləğv etməyə imkan verir. ML-DSA imzası təqdim etməklə mülkiyyət məhdudiyyətini keçən hücumçular özbaşına açarları ləğv edə bilərlər. Bu problemi aradan qaldırmaq üçün 1.4.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the `openssl_encrypt` library are affected by CVE-2026-74877?
This vulnerability affects versions of the `openssl_encrypt` library before 1.4.0.
What remediation is recommended for CVE-2026-74877?
Users are advised to upgrade the `openssl_encrypt` library to version 1.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.