Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-74899

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 40.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-74899


Contact Us

Shodan ® - All rights reserved