What is CVE-2026-74895?
This vulnerability in openssl_encrypt versions before 1.4.0 fails to enforce sandbox restrictions in the default process isolation mode for plugin execution. Attackers can exploit malicious plugins to gain unrestricted access to the filesystem, network, subprocess execution, and all Python modules. Users are advised to upgrade to version 1.4.0.
Azərbaycanca: Bu boşluq openssl_encrypt kitabxanasının 1.4.0-dan əvvəlki versiyalarında default process isolation rejimində sandbox məhdudiyyətlərinin tətbiq edilməməsinə imkan verir. Nəticədə, hücumçu pluginlərin icrası zamanı fayl sistemi, şəbəkə, subproses icrası və bütün Python modullarına məhdudiyyətsiz giriş əldə edə bilər. İstifadəçilərə openssl_encrypt-i 1.4.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
On which operating systems can the CVE-2026-74895 vulnerability be exploited?
The text does not specify an operating system, but since the vulnerability is in the openssl_encrypt library, all platforms supported by this library may be potential targets.
What is the CVSS score for CVE-2026-74895?
The CVSS score is not mentioned in the text, but the complete bypass of sandbox restrictions and unrestricted access to filesystem, network and other resources indicate a critical-level vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.