Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-74877

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 17.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-74877


Contact Us

Shodan ® - All rights reserved