SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74882

HIGH · CVSS 7.5 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.0 are vulnerable due to an insecure default configuration that erroneously trusts the entire RFC 1918 private address space in the IntegrityProxyConfig trusted_proxies. This flaw allows attackers on private networks to forge client certificate headers, potentially bypassing mTLS authentication if ProxyAuth validation is not properly enforced. Organizations using affected versions of OpenSSL should prioritize updating to mitigate the risk of unauthorized access and ensure robust authentication mechanisms.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74882
Severity
HIGH
CVSS
7.5
EPSS
0.13%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.

Related CVEs

Other vulnerabilities affecting the same vendor(s)