MEDIUMVulnerability
CVE-2026-74881
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
Properties
- severity
- MEDIUM
- score
- 6.5
- epss_score
- 0.0028
- cve_id
- CVE-2026-74881
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-08-17T11:16:42.723
- last_modified
- 2026-09-08T20:28:37.587
- epss_percentile
- 0.20225
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Permissive Cross-domain Security Policy with Untrusted Domains
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph