← Browse

CVE-2026-74894

Medium

Elevated severity or exploit probability.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.4%
31.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-287
Published 2026-08-17 · modified 2026-09-01

Description

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.

Affected

jahlives

References

Official: NVD · CVE.org