CVE-2026-74892
Last modified
CVE-2026-74892 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74892?
How severe is CVE-2026-74892?
How do I fix CVE-2026-74892?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74887openssl_encrypt before 1.4.0 imports Python's non-cryptograp…0
- CVE-2026-74888openssl_encrypt versions before 1.4.0 use a non-standard PBK…7.5
- CVE-2026-74889openssl_encrypt versions before 1.4.0 use HKDF with no salt …9.8
- CVE-2026-7489CTMS developed by Sunnet has a SQL Injection vulnerability, …8.8
- CVE-2026-74890openssl_encrypt versions before 1.4.0 contain an authenticat…5.5
- CVE-2026-74891openssl_encrypt versions before 1.4.0 contain hardcoded data…9.8
- CVE-2026-74893openssl_encrypt versions before 1.4.0 contain hardcoded defa…8.8
- CVE-2026-74894openssl_encrypt before 1.4.0 contains an authentication bypa…9.8
- CVE-2026-74895openssl_encrypt versions before 1.4.0 fail to apply sandbox …9.8
- CVE-2026-74896openssl_encrypt versions before 1.4.0 contain a sandbox esca…9.8
- CVE-2026-74899openssl_encrypt versions before 1.4.0 contain a sandbox esca…9.8
- CVE-2026-7490CTMS and CPAS developed by Sunnet has an Arbitrary File Uplo…7.2
Are you affected by CVE-2026-74892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
