CVE-2026-74883

8.8

Jahlives · openssl_encrypt

A protection mechanism failure in openssl_encrypt allows for sandbox escapes through pathlib and I/O manipulations, potentially enabling unauthorized system access.

Executive summary

A high-severity sandbox bypass vulnerability exists in the jahlives openssl_encrypt package, which could allow an unauthenticated attacker to compromise system integrity.

Vulnerability

This vulnerability, identified as CWE-693, constitutes a protection mechanism failure. The vulnerability allows for sandbox escapes via pathlib and I/O operations, and it can be triggered by an unauthenticated attacker requiring user interaction.

Business impact

The ability to bypass sandbox protections represents a critical security failure, as it allows attackers to gain unauthorized access to underlying system resources. With a CVSS score of 8.8, the potential for total system compromise is high, which could lead to widespread data loss or unauthorized administrative access.

Remediation

Immediate Action: Update to version 1.4.0 or the latest available release to address this sandbox bypass vulnerability.

Proactive Monitoring: Review system and application logs for unusual file system access or suspicious process execution that may indicate an attempted sandbox escape.

Compensating Controls: Deploy endpoint protection and runtime application self-protection tools to detect and block unauthorized file system or I/O access attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the evidence of a proof-of-concept and the high severity score, organizations must treat this vulnerability with urgency. Ensure all instances of the affected software are updated to version 1.4.0 to effectively close the identified security gap.

More Jahlives CVEs