Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74894: jahlives openssl_encrypt allows unauthorized key changes

CVE-2026-74894 · published 1 month ago
Summary

The jahlives openssl_encrypt library (versions before 1.4.0) does not properly check the login token, so anyone who can send a request can add, view, or delete encryption keys used by the system. This could let attackers tamper with secure communications or lock out legitimate users. Upgrade the library to version 1.4.0 or later and review the keys that have been created.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74894 · MITRE
Track software like this
Free during beta