SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74892

HIGH · CVSS 7.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.0 are vulnerable due to a hardcoded default secret key in the standalone telemetry server configuration, which is used for hashing API keys. This flaw allows attackers with knowledge of the default key to predict or forge API key hashes, potentially compromising telemetry API authentication. Organizations using affected versions of OpenSSL should prioritize this vulnerability to safeguard their API security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74892
Severity
HIGH
CVSS
7.5
EPSS
0.31%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

Related CVEs

Other vulnerabilities affecting the same vendor(s)