What is CVE-2026-74896?
A sandbox escape vulnerability in openssl_encrypt versions before 1.4.0 allows attackers to bypass restrictions via dunder attribute traversal chains in the DangerousPatternVisitor AST analyzer. Immediate update to version 1.4.0 or later is required.
Azərbaycanca: openssl_encrypt 1.4.0-dən əvvəlki versiyalarda DangerousPatternVisitor AST analizatorunda sandbox escape zəifliyi aşkar edilib. Təcavüzkar dunder atribut zəncirləri ilə məhdud funksiyalara çıxış əldə edə bilər; dərhal 1.4.0 və ya daha yeni versiyaya yenilənməlidir.
FAQ2
Which versions of openssl_encrypt are affected by the discovered sandbox escape vulnerability?
The CVE-2026-74896 vulnerability affects openssl_encrypt versions before 1.4.0.
How can an attacker exploit this sandbox escape vulnerability?
An attacker can access restricted functions through dunder attribute traversal chains in the DangerousPatternVisitor AST analyzer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.