CVE-2026-74886
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.38%
- CWE
- CWE-184
- Published
- 2026-08-17
- Last modified
- 2026-08-17
Affected products
- jahlives openssl_encrypt
- jahlives openssl_encrypt
Weakness type
Related vulnerabilities
- CVE-2026-87911 — Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
- CVE-2026-85788 — Incomplete list of disallowed inputs in awslabs mysql-mcp-server
- CVE-2026-86199 — PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login
- CVE-2026-79696 — Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
- CVE-2026-82536 — Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator
- CVE-2026-69624 — Active Directory Certificate Services (AD CS) Tampering Vulnerability
- CVE-2026-70334 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-33197 — BDS Module Bypass Secure Boot Advisory