CVE-2026-74899: openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy
opensslencrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via class.mro.subclasses() to access system functions and execute arbitrary OS commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
openssl_encryptto a version that resolves this vulnerability.Fixed in 1.4.0 - Upgrade
Upgrade
IsolatedPluginExecutorto a version that resolves this vulnerability.Fixed in 1.4.0Patch Sandbox Escape via Type Hierarchy
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74899?
CVE-2026-74899 has a critical severity rating of 9.8.
How do I fix CVE-2026-74899?
To fix CVE-2026-74899, upgrade to openssl_encrypt version 1.4.0 or later.
What type of vulnerability is CVE-2026-74899?
CVE-2026-74899 is a sandbox escape vulnerability.
What could an attacker do with CVE-2026-74899?
An attacker could exploit CVE-2026-74899 to execute arbitrary system functions by accessing Python type objects.
Which versions of OpenSSL are affected by CVE-2026-74899?
CVE-2026-74899 affects all versions of openssl_encrypt prior to 1.4.0.