CVE-2026-74873: Jahlives OpenSSL Encrypt

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.

Affected products

  • Jahlives OpenSSL Encrypt: before 1.4.0 (fixed in 1.4.0)

Published 2026-08-17. Last modified 2026-10-08.