Security Advisory

CVE-2026-74888

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 11:04:52
Last updated 2026-08-17 12:48:36
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.