CVE-2026-74901: openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback
opensslencrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSSL openssl_encrypt (pqc.py AES-CTR fallback)to a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74901?
CVE-2026-74901 has a critical severity rating of 9.8.
How do I fix CVE-2026-74901?
To fix CVE-2026-74901, upgrade to openssl_encrypt version 1.4.0 or later.
What type of vulnerability is CVE-2026-74901?
CVE-2026-74901 is an authentication bypass vulnerability due to AES-GCM decryption failures.
What can attackers do with CVE-2026-74901?
Attackers can exploit CVE-2026-74901 to modify ciphertext in transit and bypass integrity verification.
Which software is affected by CVE-2026-74901?
The vulnerability affects the openssl_encrypt module of OpenSSL before version 1.4.0.