LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-74892

jahlives · openssl encrypt

Published
CVSS7.5
Severityhigh
WeaknessCWE-798
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74892

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74892.