What is CVE-2026-74888?
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction, making password cracking more efficient for attackers. This vulnerability weakens encryption strength in affected systems, requiring an immediate upgrade to version 1.4.0 or above.
Azərbaycanca: openssl_encrypt kitabxanasının 1.4.0-dan əvvəlki versiyalarında qeyri-standart PBKDF2 açar törətmə konstruksiyası istifadə olunur ki, bu da parolların daha sürətli sındırılmasına şərait yaradır. Bu zəiflik təsirlənmiş versiyalardan istifadə edən sistemlərdə şifrələmə gücünü azaldır, ona görə də dərhal 1.4.0 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
Which versions of openssl_encrypt are affected by CVE-2026-74888?
Versions of the openssl_encrypt library before 1.4.0 are affected by this vulnerability.
How can CVE-2026-74888 be exploited?
This vulnerability makes password cracking more efficient due to a non-standard PBKDF2 key derivation construction.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.