MEDIUMVulnerability

CVE-2026-74890

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.

Properties

severity
MEDIUM
score
5.5
epss_score
0.00155
cve_id
CVE-2026-74890
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-17T11:16:43.960
last_modified
2026-09-01T15:26:20.103
epss_percentile
0.04914

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Insufficient Verification of Data Authenticity

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74890 — Ninja Signal Threat Intelligence | Ninja Signal