SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74896

CRITICAL · CVSS 9.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.0 are vulnerable to a critical sandbox escape flaw in the openssl_encrypt function, allowing attackers to exploit dunder attribute traversal techniques to access restricted functions. This vulnerability enables the execution of arbitrary system commands from plugin code, posing a significant risk to systems utilizing affected versions. Organizations using OpenSSL should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74896
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.

Related CVEs

Other vulnerabilities affecting the same vendor(s)