What is CVE-2026-74886?
The openssl_encrypt plugin before version 1.4.0 contains a sandbox bypass vulnerability where PluginImportGuard and the AST analyzer block different sets of dangerous modules. Attackers can exploit this by using string obfuscation to import unblocked critical modules. Upgrading to version 1.4.0 or later is recommended to mitigate this issue.
Azərbaycanca: openssl_encrypt plagini 1.4.0-dən əvvəlki versiyalarda sandbox bypass zəifliyi aşkarlanıb. PluginImportGuard və AST analizatoru müxtəlif təhlükəli modul dəstlərini blokladığına görə, attacker string obfuscation vasitəsilə qorunan modulları idxal edə bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
FAQ2
Which versions of the openssl_encrypt plugin are affected by CVE-2026-74886?
This sandbox bypass vulnerability affects versions of the plugin prior to 1.4.0.
How can an attacker import dangerous modules in CVE-2026-74886?
Since PluginImportGuard and the AST analyzer block different sets of modules, an attacker can use string obfuscation to import critical modules that remain unblocked.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.