HIGHVulnerability

CVE-2026-74888

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.

Properties

severity
HIGH
score
7.5
epss_score
0.00167
cve_id
CVE-2026-74888
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-17T11:16:43.653
last_modified
2026-09-01T15:26:41.833
epss_percentile
0.06185

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Use of a Broken or Risky Cryptographic Algorithm

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74888 — Ninja Signal Threat Intelligence | Ninja Signal