Sandbox Bypass Vulnerability in OpenSSL_Encrypt by Jahlives
CVE-2026-74883

8.7HIGH

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
17 August 2026

What is CVE-2026-74883?

OpenSSL_Encrypt versions prior to 1.4.0 are susceptible to a sandbox bypass vulnerability. This flaw allows attackers to utilize the Python modules pathlib and io, circumventing the intended file access restrictions. As a result, malicious actors can read and write arbitrary files, breaching security measures that are supposed to limit access to files within a restricted environment. This vulnerability underlines the importance of regularly updating software to mitigate potential security issues.

Affected Version(s)

openssl_encrypt 0 < 1.4.0

openssl_encrypt 1.4.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.