HIGHVulnerability

CVE-2026-74883

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.

Properties

severity
HIGH
score
8.8
epss_score
0.00257
cve_id
CVE-2026-74883
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
published_at
2026-08-17T11:16:42.993
last_modified
2026-09-01T15:27:18.940
epss_percentile
0.17192

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74883 — Ninja Signal Threat Intelligence | Ninja Signal