Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them. | |
| Title | openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:47.698Z
Reserved: 2026-08-17T10:36:18.506Z
Link: CVE-2026-74881
No data.
Status : Received
Published: 2026-08-17T11:16:42.723
Modified: 2026-08-17T11:16:42.723
Link: CVE-2026-74881
No data.
OpenCVE Enrichment
No data.
-
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains