What is CVE-2026-74883?
A sandbox bypass vulnerability (CVE-2026-74883) was found in openssl_encrypt plugin versions before 1.4.0. The flaw fails to restrict alternative file access methods like pathlib.Path and io.open, allowing attackers to completely bypass the restricted execution environment and read/write arbitrary files. Users should immediately upgrade to version 1.4.0 or later.
Azərbaycanca: openssl_encrypt plagininin 1.4.0-dən əvvəlki versiyalarında sandbox bypass zəifliyi (CVE-2026-74883) aşkar edilib. Bu boşluq sayəsində hücumçular pathlib.Path və io.open kimi alternativ fayl giriş metodlarından istifadə edərək, məhdudlaşdırılmış əməliyyat mühitindən yan keçə və ixtiyari faylları oxuya/yaza bilərlər. Plagindən istifadə edən sistemlər dərhal 1.4.0 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What is the CVE-2026-74883 vulnerability in the openssl_encrypt plugin?
It is a sandbox bypass vulnerability. In versions before 1.4.0, the plugin fails to restrict alternative file access methods like pathlib.Path and io.open, allowing an attacker to bypass the restricted execution environment and read or write arbitrary files.
How can I protect against CVE-2026-74883?
You should immediately upgrade the openssl_encrypt plugin to version 1.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.