Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74895: openssl_encrypt before 1.4.0 allows malicious plugins full system access

CVE-2026-74895 · published 1 month ago
Summary

Versions of jahlives/openssl_encrypt released before 1.4.0 do not enforce the built‑in sandbox for plugin code. This lets a attacker run a crafted plugin that can read, modify, or delete files, use the network, start other programs, and import any Python module. Update to version 1.4.0 or later, or disable third‑party plugins until the fix is applied.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74895 · MITRE
Track software like this
Free during beta