Skip to content
COOEY

EXPOSURES › CVE-2026-74895

CVE-2026-74895

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-17 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-74895 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.