openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them. | |
| Title | openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:47.698Z
Reserved: 2026-08-17T10:36:18.506Z
Link: CVE-2026-74881
No data.
Status : Received
Published: 2026-08-17T11:16:42.723
Modified: 2026-08-17T11:16:42.723
Link: CVE-2026-74881
No data.
OpenCVE Enrichment
Updated: 2026-08-17T12:45:03Z
Weaknesses