UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

CVE-2026-74892Published 2 weeks agoUpdated 5 days agoSource: OSV

Affected packages

  • openssl-encryptbefore 1.4.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur | HackTribune