What is CVE-2026-74891?
CVE-2026-74891 involves hardcoded database credentials in standalone server configuration files of openssl_encrypt versions prior to 1.4.0. Attackers on the same network can exploit these well-known default credentials to access PostgreSQL databases and retrieve sensitive data. Immediate update to version 1.4.0 or later is strongly recommended.
Azərbaycanca: CVE-2026-74891, openssl_encrypt modulunun 1.4.0-dan əvvəlki versiyalarında standalone server konfiqurasiya fayllarında sərt kodlaşdırılmış verilənlər bazası etimadnamələrinə aiddir. Eyni şəbəkədəki təcavüzkarlar bu standart etimadnamələrdən istifadə edərək PostgreSQL verilənlər bazasına giriş əldə edə və həssas məlumatları əldə edə bilərlər. Dərhal openssl_encrypt-i 1.4.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of openssl_encrypt are affected by CVE-2026-74891?
Versions prior to 1.4.0 are affected.
Which database can an attacker access using CVE-2026-74891?
A PostgreSQL database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.