What is CVE-2026-74893?
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py. This flaw allows attackers with source code access to forge valid JWT tokens for any client_id, gaining unauthorized access to keyserver and telemetry APIs. Immediate upgrade to version 1.4.0 and rotation of all default secrets is required.
Azərbaycanca: openssl_encrypt 1.4.0-dan əvvəlki versiyalarda config.py faylında sərt kodlaşdırılmış standart JWT imzalama sirri aşkar edilib. Bu boşluq təcavüzkarlara mənbə koduna çıxışla istənilən client_id üçün etibarlı JWT tokenləri yaradaraq keyserver və telemetry API-lərinə icazəsiz giriş əldə etməyə imkan verir. Dərhal 1.4.0 versiyasına yenilənməli və bütün standart sirrlər dəyişdirilməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of openssl_encrypt are affected by CVE-2026-74893?
This vulnerability affects openssl_encrypt versions before 1.4.0.
What can an attacker gain by exploiting CVE-2026-74893?
If an attacker gains source code access, they can forge valid JWT tokens for any client_id, gaining unauthorized access to keyserver and telemetry APIs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.