What is CVE-2026-74890?
openssl_encrypt library versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher. When the PYTEST_CURRENT_TEST environment variable is set, HMAC tag generation and verification is disabled, allowing attackers with code execution to produce unauthenticated ciphertext. Users should immediately upgrade to the latest version.
Azərbaycanca: openssl_encrypt kitabxanasının 1.4.0-dan əvvəlki versiyalarında autentifikasiya bypass zəifliyi aşkarlanıb. PYTEST_CURRENT_TEST mühit dəyişəninin təyin edilməsi ilə CamelliaCipher-də HMAC tag yaradılması və doğrulanması deaktiv edilir ki, bu da autentifikasiya olunmamış şifrəli mətnin yaradılmasına imkan verir. İstifadəçilər dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the openssl_encrypt library are affected by CVE-2026-74890?
Versions before 1.4.0 are affected.
How does the authentication bypass occur in CVE-2026-74890?
When the PYTEST_CURRENT_TEST environment variable is set, HMAC tag generation and verification is disabled in CamelliaCipher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.