CVE-2026-74894
opensslencrypt before 1.4.0 contains an authentication bypass vulnerability in the verifyapi_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74894.json, https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-4g2c-wpgj-49w8, https://nvd.nist.gov/vuln/detail/CVE-2026-74894, https://www.vulncheck.com/advisories/openssl-encrypt-before-authentication-bypass-via-bearer-token