What is CVE-2026-74892?
CVE-2026-74892 involves a hardcoded default secret key in the telemetry server of 'openssl_encrypt' versions before 1.4.0, used for API key hashing. Attackers can exploit this to predict or forge hashes and compromise telemetry API authentication. Affected users should urgently upgrade to version 1.4.0 or later.
Azərbaycanca: CVE-2026-74892 'openssl_encrypt' kitabxanasının 1.4.0-dan əvvəlki versiyalarında telemetriya serverində 'default secret key' kodlaşdırılıb. Təcavüzkarlar bu açarı bilərək API açar heşlərini təxmin edib autentifikasiyanı poza bilərlər. Təcili tədbir kimi kitabxananı ən azı 1.4.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which library is affected by CVE-2026-74892 and what is the secure version?
The vulnerability affects versions of the 'openssl_encrypt' library before 1.4.0. It is recommended to upgrade to version 1.4.0 or later for secure use.
What can an attacker achieve by exploiting CVE-2026-74892?
Attackers can predict or forge API key hashes due to the hardcoded default secret key in the telemetry server, thereby compromising telemetry API authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.